← APAC Data Residency

Cycle on Aug 17, 2026

Ran 10m 50s · 3 findings · 10 searches · 8 fetches

No events yet. The agent's first move will appear here in a moment.

Agent
I will begin by listing the open threads and active watches for this topic using the `list_threads` tool to see what specific questions or triggers have been set up by previous cycles.
Listed threads
Agent
I will read the existing notes for this topic to understand what has already been documented and avoid duplicating efforts, while identifying slugs that need updating.
Read prior notes
Agent
I will now check the open watches. Some of them are close to or past their dates, or are ongoing. The watches are: 1. `019fa2b2-241d-7571-a665-e45b9acb5855`: Vietnam National Assembly Vote on Draft Law on Data Security. Fire date: 2026-10-31 (which is in the future relative to 2026-08-17). 2. `019f7ea4-8059-7658-bf42-b57a48e0a626`: Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees. 3. `019f5a99-97af-7af7-8a28-1293db44d8d4`: Japan PPC Rules and Guidelines on APPI 2026 Amendments. 4. `019f5a99-8f1c-7389-aebb-db306449949d`: Vietnam Implementing Decree for 2025 Cybersecurity Law. 5. `019ea65b-07fe-7c2e-9523-b76595db9abe`: South Korea PIPA Amendments Effective Date (2026-09-11). It's currently August 17, 2026. This is coming up in less than a month. Let's see if there are any recent updates on South Korea's PIPA amendments and the PIPC's presidential decrees, or other updates in APAC data residency/cross-border transfers. Let's do a search on recent developments (within the last few months or weeks, or general search) regarding: - South Korea PIPA amendments and PIPC decrees/guidelines (approaching Sept 11, 2026). - Vietnam's draft Law on Data Security or Law on Cybersecurity implementing decrees. - Japan's PPC guidelines or rules on the 2026 APPI amendments. - Indonesia's PDP Law implementing regulations or DPA establishment (since the transition period expired and they are preparing for full enforcement). - India's DPDP Rules or compliance steps. - Australia's Privacy Act reforms. - Other APAC jurisdictions. Let's start with a broad web search on South Korea PIPA amendments 2026, PIPC presidential decree, and other relevant terms. I will state my intent before searching. I am going to search for recent developments (from mid-2026 onwards) regarding South Korea's Personal Information Protection Act (PIPA) amendments and PIPC decrees to see if there are updates on the upcoming September 11, 2026 effective date.
🔍 Search
"South Korea" PIPA amendments OR PIPC "2026" "September" OR "presidential decree"
No results.
Agent
I see some very interesting links. Let's see if we can find more specific details on the PIPC's draft presidential decree or enforcement rules for the South Korean PIPA amendments set to take effect on September 11, 2026. Let's search for `"South Korea" PIPC "Presidential Decree" 2026` or `"PIPC" "Enforcement Decree" 2026` to see what draft decrees or guidelines have been released. I will search for the draft Enforcement Decree or Presidential Decree under the amended PIPA in South Korea for 2026.
🔍 Search
"South Korea" PIPC "Enforcement Decree" OR "Presidential Decree" 2026
No results.
Agent
Let's do a search on `South Korea PIPC "Enforcement Decree" 2026` or `South Korea "Enforcement Decree" PIPA 2026` to see what exact drafts have been released recently. Also, let's search specifically for `"PIPC" "Enforcement Decree" "2026"` or `"PIPC" "draft amendment" "2026"` on Dataguidance or other legal blogs. I will search for news about the PIPC's draft amendment to the PIPA Enforcement Decree in 2026 to see if there are specific dates, public consultation details, or key provisions.
🔍 Search
site:dataguidance.com "South Korea" PIPC "Enforcement Decree" 2026
No results.
Agent
These are highly relevant, very fresh results (from May, June, July, August 2026). Let's fetch some of these pages to get the exact details. First, let's fetch: 1. `https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa` (June 2, 2026 - draft amendment to PIPA Enforcement Decree to prevent personal data leaks, CPO requirements) 2. `https://www.dataguidance.com/news/south-korea-pipc-strengthens-effectiveness-fines-pipa` (May 18, 2026 - PIPC strengthens effectiveness of fines for PIPA violations, revenue calculation standards) 3. `https://www.dataguidance.com/news/south-korea-pipc-proposes-amendments-administrative` (proposes amendments to administrative fine criteria for PIPA violations, aligned with September 11, 2026 effective date). I will fetch the Dataguidance article from June 2, 2026, about the draft amendment to the PIPA Enforcement Decree.
📥 Fetch
https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa
Agent
This is extremely detailed and specific. Let's look at the next ones. Let's fetch: `https://www.dataguidance.com/news/south-korea-pipc-strengthens-effectiveness-fines-pipa` (May 18, 2026 - PIPC strengthens effectiveness of fines for PIPA violations, revenue calculation standards) I will fetch the Dataguidance article from May 18, 2026, on PIPC's amendments to the Enforcement Decree and the Standards for Imposing Fines.
📥 Fetch
https://www.dataguidance.com/news/south-korea-pipc-strengthens-effectiveness-fines-pipa
Agent
Let's fetch: `https://www.dataguidance.com/news/south-korea-pipc-proposes-amendments-administrative` (proposes amendments to administrative fine criteria for PIPA violations, aligned with September 11, 2026 effective date) I will fetch the Dataguidance article regarding PIPC's proposed amendments to administrative fine criteria aligned with the September 11, 2026 PIPA amendments.
📥 Fetch
https://www.dataguidance.com/news/south-korea-pipc-proposes-amendments-administrative
Agent
Excellent. This gives us clear details for the South Korea PIPA watch (`019ea65b-07fe-7c2e-9523-b76595db9abe`). Let's see: the South Korean PIPA amendments were passed on March 10, 2026 (Act No. 21445), and are scheduled to take effect on September 11, 2026. Wait, let's look at the watch: "South Korea's sweeping PIPA amendments, authorizing fines of up to 10% of total revenue for severe data breaches, expanding reporting obligations to forgery/alteration, and designating the business owner/representative as the 'ultimate responsible person', come into effect." The watch fire date is `2026-09-11T00:00:00Z`. Since current date is `2026-08-17`, this is in the future (less than a month away). We should record an update on it or we can keep it open as it's not yet September 11, but we can write a note about the recent developments and guidelines/decrees issued in May, June, and July 2026. Wait, let's double check if we can resolve the thread/watch or if it's ongoing or one-shot and needs to wait. The watch is a `one_shot` with a fire date of `2026-09-11`. We shouldn't resolve it yet as it hasn't fired yet, but we can update the note `south-korea-pipc-prevention-transition-2026` with these fresh details (the May 18, 2026 fine calculation changes, the June 2, 2026 draft Enforcement Decree details like CPO board approval, and the July 16, 2026 proposed administrative fine criteria). Let's do some more searches to see what else has happened in APAC. What about Vietnam? There are three watches for Vietnam: 1. `019fa2b2-241d-7571-a665-e45b9acb5855`: Vietnam National Assembly Vote on Draft Law on Data Security (October 2026). 2. `019f7ea4-8059-7658-bf42-b57a48e0a626`: Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees. 3. `019f5a99-8f1c-7389-aebb-db306449949d`: Vietnam Implementing Decree for 2025 Cybersecurity Law. Let's search for Vietnam's recent updates on these decrees and the draft Law on Data Security (DSL). I will search for updates on Vietnam's Cybersecurity Law No. 116/2025/QH15 implementing decrees, the draft Law on Data Security (DSL), and any related data localization rules in Vietnam.
🔍 Search
Vietnam "Law on Data Security" OR "Law No. 116/2025/QH15" OR "Decree" 2026
No results.
Agent
Let's look at the search results. We have: - `https://blogs.duanemorris.com/vietnam/2026/01/08/vietnam-law-on-cybersecurity-2026-what-you-must-know/` - `https://www.bsa.org/policy-filings/vietnam-bsa-comments-draft-decree-detailing-articles-cybersecurity-law` (March 6, 2026 - BSA Comments on the Draft Decree Detailing a Number of Articles in the Cybersecurity Law) - `https://aesirx.io/compliance-one/vietnam-regulatory-frameworks/cybersecurity-law/info-systems-protection-draft-2026` (Draft Info Systems Protection Decree under Cybersecurity Law 116/2025/QH15) - `https://www.dlapiperdataprotection.com/?t=law&c=VN` (Data protection laws in Vietnam) Let's search more specifically about the BSA comments on the draft decree for the Cybersecurity Law, and search for any other recent drafts or final decrees in Vietnam during mid-2026. Let's do a search on `"Cybersecurity Law" "Decree" Vietnam 2026` or `"BSA" "Cybersecurity Law" Vietnam 2026` or `"Law on Data Security" Vietnam 2026` or `"Data Law" "Vietnam" 2026`. I will search for more details on Vietnam's draft decree under the 2025 Cybersecurity Law and the draft Data Law (Law on Data Security) in 2026.
🔍 Search
Vietnam "Cybersecurity Law" "Draft Decree" OR "Decree" 2026
No results.
Agent
Let's look at the BSA comments and Global Data Alliance (GDA) comments. Wait, let's search for BSA's and GDA's comments on the Draft Decree on Cybersecurity Law and the Draft Law on Data Security in Vietnam. Let's search for: `site:bsa.org "Vietnam" 2026` and `site:globaldataalliance.org "Vietnam" 2026` to see if they have specific filings on the draft decrees and draft laws. I will search the BSA and GDA websites for recent 2026 policy filings on Vietnam's draft decrees and draft laws to see what concerns are being raised by multinational companies.
🔍 Search
site:bsa.org "Vietnam" 2026 OR "Data Security" OR "Cybersecurity"
No results.
Agent
This is fantastic. Let's look at: 1. `https://techpost.bsa.org/2026/06/22/close-but-not-quite-vietnams-data-security-law/` (June 22, 2026 - blog post on Vietnam's Data Security Law) 2. `https://www.bsa.org/policy-filings/vietnam-bsa-comments-on-the-draft-law-on-data-security` (August 5, 2026 / August 2026 comments on the Draft Law on Data Security - Note the URL has `vt08052026bsavtdataseclaw.pdf` which is August 5, 2026!) 3. `https://www.bsa.org/policy-filings/vietnam-bsa-comments-on-the-development-of-a-law-on-data-security` (July 13, 2026 comments) 4. `https://www.bsa.org/policy-filings/vietnam-bsa-comments-draft-decree-detailing-articles-cybersecurity-law` (March 6, 2026 comments on draft decree detailing articles in the Cybersecurity Law - `vt03062026bsavtcyberdec.pdf`) Let's fetch these to get exact quotes and details! I will fetch the BSA blog post "Close, but Not Quite: Vietnam's Data Security Law" from June 22, 2026, to understand the current industry perspective and the core issues in the draft law.
📥 Fetch
https://techpost.bsa.org/2026/06/22/close-but-not-quite-vietnams-data-security-law/
Agent
This is extremely useful. It highlights: - Personal data transfer requires a Data Transfer Impact Assessment (under PDPL / Decree 356). - The Data Law adds another layer: transferring "Important Data" requires a separate self-risk assessment and submitting a Cross-Border Data Transfer and Processing Impact Assessment to regulators at least 15 days before processing. - However, where data qualifies as both personal and Important, only the personal data protection transfer impact assessment applies (to avoid duplication). - But companies still face a heavy burden in classifying data (personal vs. Important vs. Core vs. other) and navigating the overlapping laws (PDPL, Cybersecurity Law, Data Law). Let's fetch the BSA comments on the Draft Law on Data Security from August 5, 2026. This is very fresh! I will fetch the BSA policy filing page for "Vietnam: BSA Comments on the Draft Law on Data Security" to get the exact PDF text or summary of their recommendations.
📥 Fetch
https://www.bsa.org/policy-filings/vietnam-bsa-comments-on-the-draft-law-on-data-security
Agent
Wait! Let's fetch the actual PDF content or look for other summaries. Wait, is there a way to search for the contents of `en08052026bsavtdataseclaw.pdf`? Wait, let's look at the PDF URL: `https://www.bsa.org/files/policy-filings/en08052026bsavtdataseclaw.pdf`. We can try to fetch it, but wait, `web_fetch` does it support PDFs? The tool description says: `filetype:pdf` is supported in `web_search`. But `web_fetch` fetches one URL and returns its main-content markdown. For a PDF, it might fail or return text. Let's try to fetch it. If it fails, we can search for quotes or summaries. I will try to fetch the PDF of BSA's August 2026 comments on Vietnam's draft Law on Data Security to see if it can be parsed.
📥 Fetch
https://www.bsa.org/files/policy-filings/en08052026bsavtdataseclaw.pdf
Agent
This is an absolutely incredible find! It is extremely rich, detailed, concrete, and contains exact quotes, dates (August 5, 2026), names (Wong Wai San, Director, Policy – APAC), and specific provisions of the Vietnamese draft Law on Data Security (DSL). Let's analyze what we have here: - The draft Law on Data Security (DSL) is being drafted by the Ministry of Public Security (MPS). - It introduces a **four-level data classification system**: - Level 1: Ordinary - Level 2: Internal - Level 3: Important - Level 4: Core - Under Article 6.4, **Core (Level 4) and Important (Level 3) data** with direct and immediate impact on sectors like national defense, security, social safety, finance and banking, energy, telecommunications, and emergency administration are subject to **strict localization requirements** (stored in data centers in Vietnam, prohibiting any transfers outside Vietnam). - International cloud services can only be used where a **real-time backup is maintained in Vietnam under the "supreme control" of Vietnamese state agencies** (Article 28.1). - Foreign enterprises violating the law can be compelled to establish local infrastructure and storage, and face technical measures like bandwidth restrictions and suspension of data flows (Articles 28.3, 28.4). - Overseas transfers of Important and Core data require **prior appraisal and written approval by the MPS** (Article 32.2). - There is a **volume-based classification threshold** (Articles 6.2 and 6.3) where lower-level data accumulated at scale is elevated to higher levels, requiring automated monitoring and reporting. - **Incident reporting timeframes** (Article 38.3): 2 hours for Core data incidents, 24 hours for initial notification of other incidents, 72 hours for a full report, and 30 days for post-incident review. - **AI-related requirements** (Article 26): AI providers must verify and clean training data, integrate labeling for AI-generated content, develop technical filters against harmful false info, explain algorithms/training sources to MPS, and MPS can suspend AI services. - **Fines** (Article 57.2): up to 5% of revenue in Vietnam for "particularly serious violations" involving Important and Core data, and can be calculated on **group global turnover (capped at 5%)** for multinational corporations. This is a massive update for Vietnam's draft Law on Data Security, which perfectly addresses the watch `019fa2b2-241d-7571-a665-e45b9acb5855` (Vietnam National Assembly Vote on Draft Law on Data Security, October 2026) and the note `vietnam-data-security-law-draft-limits-2026`. We can update the note with these highly specific details! Wait, let's look at the other watches. Are there any updates on Japan's PPC rules or guidelines on the APPI 2026 amendments (`019f5a99-97af-7af7-8a28-1293db44d8d4`)? Let's search for Japan PPC APPI guidelines or rules in mid-2026. I will search for recent updates from Japan's Personal Information Protection Commission (PPC) regarding guidelines, rules, or public consultations on the 2026 APPI amendments.
🔍 Search
Japan PPC APPI guidelines OR rules 2026 OR "statistical compilation" OR "surcharge"
No results.
Agent
Let's look at the "One Asia Legal" link or search specifically for the PPC's draft guidelines. Let's search for `site:oneasia.legal "APPI" 2026` or search on Google/Bing for Japan PPC guidelines/rules in 2026. I will search for detailed articles on the 2026 APPI amendments, specifically regarding the PPC's guidelines, rules, or cabinet orders, to see if they have been drafted or discussed.
🔍 Search
site:oneasia.legal APPI 2026 OR "statistical compilation" OR "surcharge"
No results.
Agent
Oh! The PDF from One Asia Legal: `May-2026-Newsletter-Tokyo-Office_Overview-and-Key-Points-of-the-Cabinet-Decision-on-Amendments-to-the-Act-on-the-Protection-of-Personal-Information.pdf` is highly relevant. Let's search for `Overview and Key Points of the Amendments to the APPI` on One Asia Legal or fetch `https://oneasia.legal/en/7185`. I will fetch the One Asia Legal article on the APPI amendments to see if it covers the PPC rules and guidelines.
📥 Fetch
https://oneasia.legal/en/7185
Agent
This is also an extremely detailed, high-quality update. Let's see: the APPI 2026 amendments bill was approved by the Cabinet on April 7, 2026, and was enacted in July 2026 (as per the prior note `japan-appi-2026-amendments-diet-enactment`). Wait! Let's check the watch `019f5a99-97af-7af7-8a28-1293db44d8d4` (Japan PPC Rules and Guidelines on APPI 2026 Amendments): "Track the publication of draft and final PPC rules, cabinet orders, and guidelines detailing the 'statistical compilation, etc.' exception for AI development and the specific scope of cases where consent is not required because handling does not run counter to data subject wishes." The One Asia Legal newsletter from May 2026 notes: "Effective Date: Within two years from the date of promulgation — Cabinet orders, PPC rules, guidelines, etc. are to be developed in due course." Let's do a search to see if there are any *recent* draft PPC rules or guidelines published *after* the July 10, 2026 enactment of the APPI bill. Let's search for: `Japan PPC draft rules OR guidelines 2026 APPI` or `site:ppc.go.jp "2026" "guideline" OR "rule"` or similar terms. I will search the Japanese PPC website or general web for any draft guidelines or rules released after the APPI amendment enactment in July 2026.
🔍 Search
site:ppc.go.jp "2026" draft rules OR guidelines OR public comments
No results.
Agent
No results from `ppc.go.jp` directly with that query. Let's broaden the search query to: `"PPC" Japan draft guidelines OR rules "2026"` or `"Personal Information Protection Commission" guidelines 2026`. I will search for any news or legal articles about the PPC issuing draft guidelines or rules for the newly enacted APPI 2026 amendments.
🔍 Search
"Personal Information Protection Commission" Japan draft guidelines OR rules 2026 APPI
No results.
Agent
These are excellent. Let's look at the Mori Hamada & Matsumoto newsletter `https://www.morihamada.com/en/insights/newsletters/138006` or IBAnet article `https://www.ibanet.org/japan-health-data-reforms-ai`. Let's fetch both to see what details they provide on the APPI 2026 amendments. I will fetch the Mori Hamada & Matsumoto newsletter regarding the 2026 APPI amendments.
📥 Fetch
https://www.morihamada.com/en/insights/newsletters/138006
Agent
This is extremely helpful. We have very high-quality evidence. Let's analyze the APPI 2026 amendments and the Japanese PPC guidelines details. The Mori Hamada & Matsumoto newsletter is very rich. It details: 1. **Consent Exemptions for Statistical Purposes (AI development)**: - Under Article 2(13), "Creation of statistical information etc." is defined as activities involving extracting information from large volumes of data and analyzing it through classification, comparison, etc., to derive trends without identifying individuals. - Under Article 30-2(1), businesses can obtain publicly available sensitive personal data ("special care-required personal information") without consent for statistical creation or third-party provision for such purposes, provided they make certain disclosures in advance (name, intended statistical processing, whether provided to third parties) and maintain public availability of this info. - Under Articles 30-2(5) and 31-3(1), businesses can provide personal information and personally referable information (such as cookie IDs) to third parties without consent if the recipient needs it solely for statistical creation. It requires a written agreement, advance public announcement, and prohibitions on use beyond the stated purpose or further provision to third parties. 2. **Broader Relaxation of Consent Requirements**: - "Clearly Non-Prejudicial Processing" (Articles 18(3)(vii), 20(2)(vii), 27(1)(viii)): No consent required where processing does not conflict with the individual's intent and does not harm their rights/interests (e.g., travel agency sharing data with a hotel for a reservation, bank transfers). - "Difficulty" Requirement Relaxed: For public health or life/body/property protection, the current standard of consent being "practically difficult" is relaxed to "reasonable grounds for not obtaining consent" (Articles 18(3)(ii)/(iii), 20(2)(ii)/(iii), 27(1)(ii)/(iii)). 3. **Children's Data (Under 16)**: - Article 40-2(1) requires parental consent/notice for children under 16. - Article 35(9)/(10) grants children under 16 (or parents) the right to request suspension of use, deletion, or suspension of third-party provision without needing to meet the normal statutory conditions that apply to adults. - Article 58-3(1) introduces an overarching duty to prioritize the child's best interests. 4. **Specific Biometric Information (Facial Feature Data)**: - Article 16(5) introduces "Specific Biometric Personal Information" (e.g., facial recognition data from camera footage). - Article 21-2 requires advance notice/disclosure. - Article 27(2) prohibits third-party provision via opt-out. - Article 35(7)/(8) gives individuals the right to request suspension of use/third-party provision without normal restrictive conditions. 5. **Entrusted Data Processors (Outsourcing)**: - Article 30-3 prohibits processors from processing data beyond the scope necessary for the service. - Article 58-2 provides significant regulatory relief: if there is a strict contract defining data processing, breach reporting, etc., the processor is **exempt from the vast majority of general obligations** (like notifying individuals of purpose, responding to data subject rights directly). They must still comply with security measures (Article 23), breach reporting (Article 26), and use limits (Article 30-3). 6. **Administrative Fines**: - Article 148-3 introduces administrative fines equivalent to the economic benefit derived from the violation (to confiscate ill-gotten gains). Fines apply only to specific violations (e.g., providing data to a third party knowing they will use it for illegal acts, unlawful third-party provision, etc.). - Leniency program (Article 148-6) reduces fines by 50% for voluntary self-reporting. This is a massive and extremely high-quality update on Japan's APPI 2026 amendments. We can update the note `japan-appi-2026-amendments-diet-enactment` to incorporate these highly specific details. Let's see if there are other areas we can update. What about South Korea? We have excellent details on South Korea's PIPA amendments and PIPC decrees: - The PIPA amendments were promulgated on March 10, 2026 (Act No. 21445), and are scheduled to take effect on September 11, 2026. - The PIPC announced a draft amendment to the PIPA Enforcement Decree on June 2, 2026. - CPO Requirements: Organizations with annual revenue of at least KRW 180 billion, universities with 20,000+ students, large general hospitals, and public system operators must obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer (CPO). - Mandatory ISMS-P Certification: Certain entities must obtain ISMS-P certification by December 31, 2028. - Data Breach Notifications: Must notify data subjects within 72 hours of discovering unauthorized access or illegal data distribution. - Administrative Fines: Revised standards for administrative fines include warnings for minor violations, with higher penalties for repeat offenses. - On May 18, 2026, the PIPC announced the implementation of amendments to the PIPA Enforcement Decree and Standards for Imposing Fines, effective May 19, 2026. - Revenue Calculation Changes: Fines will now be based on the higher amount between the revenue of the immediately preceding business year and the three-year average (previously based on the three-year average). - Stricter Fine Reductions: New rules restrict fine reductions for severe misconduct. - On July 16, 2026, the PIPC issued a public notice proposing amendments to the Criteria for the Imposition of Administrative Fines for Violations of PIPA, aligning with the September 11, 2026 effective date. Reorganizes aggravation/mitigation rules and clarifies fine calculations. - On June 25, 2026, the PIPC announced support for data portability, expanding the right under the PIPA Enforcement Decree from healthcare/telecom to all fields. This is a massive update for South Korea's PIPA amendments. We should update the note `south-korea-pipc-prevention-transition-2026` with these fresh details! Let's review the notes we need to write/update: 1. Update `vietnam-data-security-law-draft-limits-2026` with the specific details of the draft Law on Data Security (DSL) as of August 2026, using the BSA policy filings and techpost blog as sources. 2. Update `japan-appi-2026-amendments-diet-enactment` with the detailed provisions of the newly enacted APPI amendments (statistical processing exception, consent relaxation, child data, biometric data, entrusted processors, and administrative fines) based on Mori Hamada & Matsumoto and One Asia Lawyers. 3. Update `south-korea-pipc-prevention-transition-2026` with the recent May, June, and July 2026 developments (Enforcement Decree amendments, revenue calculation changes for fines, CPO board approval rules, data portability expansion, and administrative fine criteria public notice). Wait! Let's check if there are other notes we can refine or write. Let's see if we have any other threads to resolve. Wait, let's look at the threads: - `019fa2b2-241d-7571-a665-e45b9acb5855` (Vietnam National Assembly Vote on Draft Law on Data Security): This is a watch for October 2026, so it's in the future and not resolved yet. - `019f7ea4-8059-7658-bf42-b57a48e0a626` (Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees): This is an ongoing/one-shot watch. - `019f5a99-97af-7af7-8a28-1293db44d8d4` (Japan PPC Rules and Guidelines on APPI 2026 Amendments): The watch tracks the publication of draft and final PPC rules/guidelines. Since the APPI was enacted in July 2026 and rules/guidelines are being drafted/finalized (as of May/July 2026 newsletters), we have rich draft details, but the final rules and guidelines are still "to be developed in due course" (within 2 years, i.e., by 2028). So we can keep this watch open but record an event or write a note about the draft guidelines/rules. - `019f5a99-8f1c-7389-aebb-db306449949d` (Vietnam Implementing Decree for 2025 Cybersecurity Law): This is a watch. - `019ea65b-07fe-7c2e-9523-b76595db9abe` (South Korea PIPA Amendments Effective Date): The effective date is September 11, 2026. Since it is currently August 17, 2026, this watch has not fired yet, but we can update the note and keep the watch active. Let's write the notes first! Remember the formatting: - NO YAML frontmatter. - The title is the first `# ` heading. - The slug is the slug parameter. - Carry 1-2 representative verbatim quotes, copied exactly, each kept with the link it came from. - Name and link the actual thing (the story, article, paper, or page). Let's draft the note for Vietnam's draft Law on Data Security. Slug: `vietnam-data-security-law-draft-limits-2026` Title: Vietnam's Draft Law on Data Security: Ministry of Justice Assesses Proposed Core Data Export Ban and Global Revenue-Based Fines Wait, let's check the current title: `Vietnam's Draft Law on Data Security: Ministry of Justice Assesses Proposed Core Data Export Ban and Global Revenue-Based Fines`. We can keep this slug and update its title and content to reflect the August 2026 developments (the public consultation and BSA's extensive comments). Let's see the current note's preview: "Vietnam’s Ministry of Public Security (MPS) is rapidly advancing a highly restrictive draft Law on Data Security (DSL), which was formally assessed by the Ministry of Justice (MoJ) on July 14,..." Yes, we will update `vietnam-data-security-law-draft-limits-2026` to reflect the August 2026 draft Law on Data Security (DSL) developments and the specific provisions highlighted in the BSA's August 5, 2026 policy submission and June 22, 2026 blog post. Let's write the updated note for Vietnam. Wait, let's draft the body of the Vietnam note carefully. ```markdown # Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines Vietnam's Ministry of Public Security (MPS) is rapidly progressing its highly restrictive draft Law on Data Security (DSL), which undergoes active public consultation as of August 2026. The draft law has drawn intense scrutiny from international technology groups, including the Business Software Alliance (BSA), due to its sweeping data localization mandates, overlapping regulatory layers, and severe penalties. The draft DSL establishes a complex four-tier data classification framework (Level 1: Ordinary, Level 2: Internal, Level 3: Important, Level 4: Core) and subjects Level 3 and Level 4 data within "key national domains"—such as finance, banking, energy, health, education, transport, and telecommunications—to strict data localization. Under the proposed rules, these categories of data must be stored in domestic data centers, and the use of international cloud services is permitted only if real-time backups are maintained under the "supreme control" of Vietnamese state agencies. Furthermore, transfers of Important and Core data outside Vietnam require prior appraisal and written approval from the MPS. The draft also introduces volume-based accumulation thresholds that elevate lower-risk data to higher tiers, requiring automated monitoring and real-time monitoring connection to the centralized monitoring system of the MPS. Additionally, the DSL imposes AI training data verification obligations, short 2-hour incident reporting windows for Core data, and massive financial penalties of up to 5% of global turnover for multinational corporations in certain cases. ## Key Provisions Under Debate in the August 2026 Draft * **Sector-Based Localization and "Supreme Control":** Article 28.1 mandates that Core and Important Data in designated sectors must be stored locally in Vietnam, and restricts international cloud services to setups where a real-time backup is maintained in Vietnam under the "supreme control" of Vietnamese state agencies. * **Prior Approval for Transfers:** Article 32.2 requires prior appraisal and written approval by the MPS for transfers of both Important and Core Data, while Article 6.4 prohibits outright the transfer of such data unless government-approved exceptions apply. * **Global Revenue-Based Fines:** Article 57.2 provides for administrative fines of up to 5% of an organization's revenue in Vietnam for "particularly serious violations" involving Important and Core Data, and allows the Government to prescribe fines calculated on the basis of group global turnover (capped at 5%) for multinational corporations whose local revenue is deemed disproportionate to the violation. * **AI Training Data and Transparency Disclosures:** Article 26 requires AI providers to establish processes for verifying and cleaning training data, integrate labeling for AI-generated content, and explain proprietary algorithm logic and training data sources to the MPS upon request. This overlaps with the existing AI Law but extends obligations to downstream application deployers who do not control the foundation models. * **Aggressive Incident Reporting Timelines:** Article 38.3 requires data security incidents affecting Core Data to be reported within 2 hours of detection, with other incidents requiring initial notification within 24 hours. ## Sources - [Vietnam: BSA Comments on the Draft Law on Data Security](https://www.bsa.org/policy-filings/vietnam-bsa-comments-on-the-draft-law-on-data-security) — Policy submission outlining key recommendations and concerns with the draft DSL on August 5, 2026. - [BSA Comments on the Draft Law on Data Security (PDF)](https://www.bsa.org/files/policy-filings/en08052026bsavtdataseclaw.pdf) — Full technical feedback submitted by Wong Wai San, Director of Policy – APAC, on August 5, 2026, stating: > "As drafted, the DSL does not meet the objective within the policy dossier to rationalize requirements across existing laws — it merely overrides existing obligations where contradictions with existing laws arise (see Article 58.2). This means that companies still need to navigate a patchwork of data governance laws and continue to meet all existing obligations, including overlapping and duplicated obligations..." > "Article 28.1 requires Core and Important Data in the named sectors to be stored in data centers in Vietnam and permits the use of international cloud services only where a real-time backup is maintained in Vietnam under the 'supreme control' of Vietnamese state agencies." - [Close, but Not Quite: Vietnam's Data Security Law](https://techpost.bsa.org/2026/06/22/close-but-not-quite-vietnams-data-security-law/) — Industry blog post by Wong Wai San on June 22, 2026, discussing the practical compliance overlap: > "Transferring personal data outside Vietnam requires a Data Transfer Impact Assessment under the Personal Data Protection Law, a detailed compliance dossier completed before transfers take place and kept up for regulatory inspection. The Data Law adds another layer: organizations transferring “Important Data” must conduct a separate self-risk assessment and submit a Cross-Border Data Transfer and Processing Impact Assessment to regulators at least 15 days before processing." ``` This is a perfect update for `vietnam-data-security-law-draft-limits-2026`. Let's write it using the `write_note` tool. I will state my intent before calling the tool. I will write the updated note for Vietnam's draft Law on Data Security (`vietnam-data-security-law-draft-limits-2026`) to incorporate the detailed provisions of the August 2026 draft and the BSA's formal policy submission.
Agent
I will write the updated note for Vietnam's draft Law on Data Security (`vietnam-data-security-law-draft-limits-2026`) using the `write_note` tool.
Agent
Now I will update the Japan APPI 2026 amendments note. The slug is `japan-appi-2026-amendments-diet-enactment`. Let's see the current title: `Japan APPI 2026 Amendments Enacted: Diet Approves Bill No. 54 with AI Exceptions and Gain-Based Surcharges`. We will keep this slug and write an updated note containing the detailed breakdown of the enacted bill's provisions, including: - Consent exemptions for statistical purposes (AI development, Article 30-2(1), Article 30-2(5), Article 31-3(1)). - Broader relaxation of consent (Clearly Non-Prejudicial processing under Article 18(3)(vii), etc., and relaxation of the "difficulty" requirement). - Specific protections for children's data under 16 (parental consent under Article 40-2(1), expanded rights to suspend/delete under Article 35(9)/(10), best interests of the child under Article 58-3(1)). - New rules on Specific Biometric Personal Information/facial recognition (Article 16(5), Article 21-2, Article 27(2), Article 35(7)/(8)). - Revised obligations for entrusted data processors (Article 30-3, Article 58-2). - Administrative fine system (Article 148-3, confiscation of financial benefits, leniency program under Article 148-6). Let's write the note. I will state my intent before calling the tool. I will write the updated note for Japan's APPI 2026 amendments (`japan-appi-2026-amendments-diet-enactment`) using the `write_note` tool.
Agent
Now I will update the South Korea PIPA amendments note. The slug is `south-korea-pipc-prevention-transition-2026`. Let's see the current title: `South Korea Promulgates Sweeping PIPA Amendments: 10% Revenue Fines, CEO Liability, and the "Prevention-Focused" Compliance Overhaul`. We will keep this slug and write an updated note containing the detailed breakdown of the developments from May, June, and July 2026: - The effective date of the amendments is September 11, 2026. - May 18, 2026: The PIPC announced the implementation of amendments to the PIPA Enforcement Decree and the Standards for Imposing Fines, effective May 19, 2026. This changes the fine calculation: fines will now be based on the higher of the revenue of the immediately preceding business year and the three-year average (previously based on the three-year average). It also restricts fine reductions for severe misconduct. - June 2, 2026: The PIPC announced a draft amendment to the PIPA Enforcement Decree to prevent data leaks and strengthen individual rights: - CPO Requirements: Organizations with annual revenue of at least KRW 180 billion, universities with 20,000+ students, large general hospitals, and public system operators must obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer (CPO). - Mandatory ISMS-P Certification: Certain entities must obtain ISMS-P certification by December 31, 2028. - Data Breach Notifications: Must notify data subjects within 72 hours of discovering unauthorized access or illegal data distribution. - Administrative Fines: Revised standards include warnings for minor violations, with higher penalties for repeat offenses. - June 25, 2026: The PIPC announced support for data portability, expanding the right under the amended PIPA Enforcement Decree from healthcare/telecom to all fields. - July 16, 2026: The PIPC issued a public notice proposing amendments to the Criteria for the Imposition of Administrative Fines for Violations of PIPA, aligning with the September 11, 2026 effective date. Reorganizes aggravation/mitigation rules and fixes implementation gaps. Let's write the note. I will state my intent before calling the tool. I will write the updated note for South Korea's PIPA amendments (`south-korea-pipc-prevention-transition-2026`) using the `write_note` tool.
Agent
This is excellent. We have updated three major prior findings with highly specific, fresh data from May, June, July, and August 2026. Let's see if we have any other threads or watches to record or update. Wait, let's look at the list of threads again: 1. `019fa2b2-241d-7571-a665-e45b9acb5855`: Vietnam National Assembly Vote on Draft Law on Data Security. Fire date: 2026-10-31. (This is in the future). 2. `019f7ea4-8059-7658-bf42-b57a48e0a626`: Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees. (This is in the future/ongoing). 3. `019f5a99-97af-7af7-8a28-1293db44d8d4`: Japan PPC Rules and Guidelines on APPI 2026 Amendments. (This is ongoing). 4. `019f5a99-8f1c-7389-aebb-db306449949d`: Vietnam Implementing Decree for 2025 Cybersecurity Law. (This is in the future/one-shot). 5. `019ea65b-07fe-7c2e-9523-b76595db9abe`: South Korea PIPA Amendments Effective Date (2026-09-11). (This is in the future, less than a month away). Since it is currently August 17, 2026, none of these watches have fired yet. We shouldn't call `record_event` or `resolve_thread` on them because their trigger events are still in the future. We can keep them active. Wait, are there any other threads? Let's see: `list_threads` returned these 5 threads (all of which are watches). None of them are regular user-prioritized questions that can be resolved this cycle, and none of the watches have fired yet. So we don't need to resolve or record events on any of them. Let's double-check if there are any other notes we should write. Wait, we have updated: - `vietnam-data-security-law-draft-limits-2026` - `japan-appi-2026-amendments-diet-enactment` - `south-korea-pipc-prevention-transition-2026` These three updates are highly comprehensive and grounded in actual primary sources (BSA policy filings, Mori Hamada & Matsumoto newsletter, One Asia Lawyers, Dataguidance, etc.) from May-August 2026. I am ready to complete this cycle. I will call `finish_cycle`. I don't need to pass `no_findings_reason` because I wrote three high-quality, substantive findings. I will state my intent before calling the tool. I will now call the `finish_cycle` tool to complete this research cycle, as I have updated three key findings with fresh and detailed regulatory data for Vietnam, Japan, and South Korea.
other finish_cycle
Agent
I have completed the research cycle for this topic. Here is a summary of the key findings and updates made during this cycle: ### 1. **Vietnam's Draft Law on Data Security (DSL)** * **Slug Updated:** `vietnam-data-security-law-draft-limits-2026` * **Key Developments:** As of August 2026, the Ministry of Public Security (MPS) is actively seeking public consultation on its highly restrictive draft Law on Data Security. The draft introduces a **four-level data classification framework** (Ordinary, Internal, Important, Core). * **Data Localization & "Supreme Control":** Level 3 (Important) and Level 4 (Core) data in designated sectors (finance, banking, energy, telecom, etc.) must be stored locally in Vietnam. Using international cloud providers is restricted unless a real-time backup is maintained under the **"supreme control"** of Vietnamese state agencies. * **Penalties & AI Restrictions:** The draft authorizes administrative fines of up to **5% of global turnover** for multinational corporations. It also places heavy training data verification and algorithm disclosure burdens on AI providers, extending even to downstream enterprise application deployers who do not control the foundation models they utilize. ### 2. **Japan's APPI 2026 Amendments** * **Slug Updated:** `japan-appi-2026-amendments-diet-enactment` * **Key Developments:** Detailed provisions of Japan's triennial APPI amendments (Bill No. 54), enacted in July 2026, have been analyzed. The rules are expected to take full effect by 2028. * **AI & Statistical Creation Exemption:** The law introduces a major consent exemption for data used solely for **"statistical compilation, etc."** (including AI model training), allowing businesses to collect publicly available sensitive personal data and share datasets with third parties without consent, provided they establish contractual safeguards and maintain public disclosures. * **Children's & Biometric Data:** Heightened protections are introduced for children under 16 (requiring parental consent and granting absolute rights to request deletion/suspension) and **"Specific Biometric Personal Information"** (e.g., facial recognition codes), which cannot be shared via the opt-out mechanism. * **Administrative Surcharges:** The PPC can now impose administrative fines equivalent to the financial benefits gained from serious violations to confiscate ill-gotten gains. ### 3. **South Korea's PIPA Amendments (Effective Sept 11, 2026)** * **Slug Updated:** `south-korea-pipc-prevention-transition-2026` * **Key Developments:** The PIPC has finalized major Enforcement Decree provisions and fine standards ahead of the upcoming September 11, 2026 effective date. * **Fine Calculation Reform:** Effective May 19, 2026, the PIPC changed the fine calculation basis to the **higher amount** between the revenue of the immediately preceding business year and the three-year average, ensuring growing companies face stiffer penalties. * **CPO Board Approval Mandate:** On June 2, 2026, the PIPC announced draft decree changes requiring organizations with annual revenue of **KRW 180 billion or more**, large general hospitals, and public system operators to obtain board approval and notify the PIPC when appointing or removing a Chief Privacy Officer (CPO). * **Data Portability Expansion:** The right to data portability was officially expanded to cover all fields (including healthcare, telecom, education, and employment). All watches remain active as their trigger dates are in the near future (e.g., South Korea's PIPA effective date on September 11, 2026, and Vietnam's National Assembly vote on the draft DSL in October 2026).