← APAC Data Residency

Cycle on Aug 24, 2026

Ran 5m 32s · 3 findings · 10 searches · 4 fetches

No events yet. The agent's first move will appear here in a moment.

Agent
I will list the open threads and read the existing notes for this topic to understand the current state of research and see what specific questions or watches are active.
Listed threads
Agent
I will read the existing notes for this topic to understand what has been documented so far.
Read prior notes
Agent
The current date is August 24, 2026. Let's look at the open threads: 1. `Vietnam National Assembly Vote on Draft Law on Data Security` (one-shot, fire_date: 2026-10-31T00:00:00Z) - this is in October 2026. 2. `Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees` (one-shot, no fire date) 3. `Japan PPC Rules and Guidelines on APPI 2026 Amendments` (ongoing) 4. `Vietnam Implementing Decree for 2025 Cybersecurity Law` (one-shot, no fire date) 5. `South Korea PIPA Amendments Effective Date` (one-shot, fire_date: 2026-09-11T00:00:00Z) - wait, this is September 11, 2026! Today is August 24, 2026, so this is very close (just 2.5 weeks away). Let's see if there are any recent updates regarding the South Korea PIPA amendments, the PIPC's guidelines, or any new presidential decrees. Let's also do a search on recent APAC data transfer and data residency regulations, amendments, and enforcement actions. Let's look for what has happened recently (e.g., in June, July, and August 2026). Let's search for: - South Korea PIPA amendments September 2026 guidelines or presidential decree. - Vietnam Draft Law on Data Security updates. - Japan PPC guidelines/rules APPI 2026. - Other APAC countries: China, India, Malaysia, Singapore, Indonesia, Australia, etc. Let's start by searching for South Korea PIPA amendments and PIPC updates.I will search for recent developments regarding South Korea's PIPA amendments, specifically looking for new PIPC guidelines, presidential decrees, or updates as the September 11, 2026 effective date approaches.
🔍 Search
"South Korea" PIPA PIPC amendments September 2026 guidelines OR decree
No results.
Agent
Let's fetch the Chambers and Partners guide page to see the details of the latest South Korea PIPA amendments (which were apparently amended on March 10, 2026, or passed in early 2026, and are taking effect on September 11, 2026). Let's fetch that page. Or wait, let's also search for the PIPC's draft amendment to the PIPA Enforcement Decree from June 2026 (mentioned in VitalLaw and DataGuidance). Let's run a query for that.I will search for details on the draft PIPA Enforcement Decree or guidelines issued by the PIPC in South Korea in mid-2026, as well as the comment period mentioned in June 2026.
🔍 Search
"PIPC" "Enforcement Decree" OR "guidelines" June OR July OR August 2026 "PIPA"
No results.
Agent
This is very interesting! Kim & Chang published an article: `PIPC Releases Proposed Amendments to the PIPA Enforcement Decree. 2026.06.05`. Let's fetch that page. Also, let's fetch the Shin & Kim article `PIPC Announces “Transition Plan toward a Prevention-Focused Personal Information Management System”` or look for more information on that. Let's do a fetch of Kim & Chang and Shin & Kim. Let's start with Kim & Chang first. I will fetch the Kim & Chang URL. I will also fetch the DataGuidance or other relevant news if needed. Let's fetch Kim & Chang first.
📥 Fetch
https://www.kimchang.com/en/insights/detail.kc?sch_section=4&idx=34971
Agent
This is incredibly detailed and useful! Let's examine what we have: South Korea's PIPA amendments were promulgated on March 10, 2026, and are taking effect on September 11, 2026. The PIPC released proposed amendments to the PIPA Enforcement Decree on June 1 and 2, 2026, with the public consultation running until July 13, 2026. Let's see what the main points are: 1. **Administrative Penalties (up to 10% of total revenue)**: - Detailed standards and procedures for calculating and imposing these penalties. - Calculation: base amount = revenue related to the violation (total revenue minus revenue unrelated to the violation) multiplied by a base rate reflecting severity. - Grounds for increasing the base amount: (i) willful/grossly negligent repeat violation within three years; (ii) willful/grossly negligent violation affecting 10 million or more data subjects; (iii) leakage due to non-compliance with a corrective order. - Reduction mechanism for privacy-protection investments: Up to 40% reduction of the base amount based on scale and continuity of privacy investments (budget, personnel, facilities, equipment), CPO role, etc. No reduction for willful or grossly negligent violations. - Penalty waiver: Where no harm (or minor harm) has occurred, the controller remedied the violation, and PIPC guidelines are satisfied. 2. **CPO Designation (Board Resolution & PIPC Reporting)**: - Scope: Annual revenue/income of KRW 180 billion or more that process sensitive/unique info of at least 50,000 data subjects OR personal info of at least 1 million data subjects. Also universities (20k+ students), tertiary general hospitals, and public system operating institutions. - Procedure: Reports of designation, change, or removal must be submitted to the PIPC within one month. 3. **Mandatory ISMS-P Certification**: - Scope: Major public system operators, mobile telecom carriers, identity verification agencies, and companies with prior-year revenue of at least KRW 1 trillion and at least KRW 10 billion in info & communications services, with average daily domestic data subjects of 30 million or more. - Deadline: December 31, 2028. 4. **Data Breach Notification**: - Must notify data subjects "without delay" not only when a breach is confirmed, but also upon recognizing a "likelihood" of a breach. - Specifically: - Unauthorized access to systems/devices and circumstances indicate personal info *may* have been breached -> notify within 72 hours of awareness, even if individual data subjects cannot be identified yet. - Unlawfully traded/distributed personal info and high likelihood of more data subjects affected -> notify within 72 hours. - Scope of notifications: includes lost, stolen, leaked, and now *forged, altered, or damaged* data. This is extremely rich and directly addresses the South Korea thread `South Korea PIPA Amendments Effective Date` (thread `019ea65b-07fe-7c2e-9523-b76595db9abe`). Wait! Let's check if there are any other updates or if the final Enforcement Decree has been officially promulgated or if there are any further announcements in August 2026. Let's do a quick search on the PIPC's website or general news for the final promulgation of the Enforcement Decree in South Korea. Today is August 24, 2026. The effective date is September 11, 2026. Let's see if the decree has been finalized.I will search for any updates from late July or August 2026 regarding the finalization or promulgation of the PIPA Enforcement Decree in South Korea.
🔍 Search
"Enforcement Decree" "PIPA" "PIPC" August OR July 2026
No results.
Agent
Let's fetch the Lexology article from August 19, 2026: `Data Privacy Update: Proposed Amendment to the...` or search for it specifically to see if there are any other details. Let's do a search for that Lexology article.I will search for the specific Lexology article from August 2026 to see what new details it provides about the South Korea PIPA Enforcement Decree or related notices.
🔍 Search
site:lexology.com "Proposed Amendment" "PIPA" "PIPC" 2026
No results.
Agent
Let's fetch the Lexology article: `Data Privacy Update: Proposed Amendment to the...` (https://www.lexology.com/library/detail.aspx?g=c24075d9-0db4-41f9-ad18-59dcf94aed49) to see what it is about. It seems to mention "privacy policy" evaluation by PIPC. Let's fetch it.
📥 Fetch
https://www.lexology.com/library/detail.aspx?g=c24075d9-0db4-41f9-ad18-59dcf94aed49
Agent
Ah! The Yulchon article is actually from **June 7, 2023**, which was about the *previous* PIPA amendments that took effect on September 15, 2023. Wait, let's look at the dates carefully. The Kim & Chang article from **June 5, 2026** says: - "The Amended PIPA ... was promulgated on March 10, 2026 and will take effect on September 11, 2026." - "The PIPC announced proposed amendments to the Enforcement Decree ... on June 1 and June 2, 2026..." This matches! So the 2026 amendments are a *new* set of amendments (promulgated March 10, 2026, taking effect September 11, 2026) that raise the cap to **10% of total revenue** for repeated or serious violations! Wait, let's verify if there was an amendment in 2023 that raised it to 3% (which is what the Yulchon 2023 article talks about), and then a *new* amendment in early 2026 that raises it to 10% for repeated/serious violations. Yes! Let's check the Chambers and Partners guide: "Under Article 64-2, paragraph 1 of the PIPA, where a violation subject to an administrative penalty occurred, the PIPC was authorised to impose an administrative penalty of up to 3% of the total turnover... The Amended PIPA introduces Article 64-2, paragraph 2, pursuant to which an administrative penalty of up to 10% of the relevant total turnover ... may be imposed ... [for repeated or intentional breaches, or serious incidents affecting 10M+ people]." And the Shin & Kim article says: "In cases of intentional or gross negligence for repeated violations within three years, or serious incidents affecting 10 million or more people, a penalty surcharge of up to 10% of annual revenue will be imposed. This represents a substantial increase from the existing 3% cap, following the amended Personal Information Protection Act (the “PIPA”) which is set to take effect on September 11, 2026." This is extremely clear and precise. Wait, let's search for more details on this. Is there any other news about South Korea's PIPA in July or August 2026? Let's search for: `South Korea PIPC August 2026` or `South Korea PIPA September 2026`. Let's see what else comes up.I will search for any other recent updates from the South Korean PIPC during August 2026, to see if there are any new guidelines, enforcement actions, or clarifications on the upcoming September 11, 2026 changes.
🔍 Search
"PIPC" OR "PIPA" August 2026 South Korea
No results.
Agent
Let's fetch the Hunton Andrews Kurth blog post `South Korea Amends Privacy Law to Authorize Fines of Up...` (https://www.hunton.com/privacy-and-cybersecurity-law-blog/south-korea-amends-privacy-law-to-authorize-fines-of-up-to-10-of-total-revenue) to see what it says about the 10% total revenue fine and the other provisions of the early 2026 amendments. Let's fetch it.
📥 Fetch
https://www.hunton.com/privacy-and-cybersecurity-law-blog/south-korea-amends-privacy-law-to-authorize-fines-of-up-to-10-of-total-revenue
Agent
This is excellent. We have solid evidence of the upcoming South Korean PIPA amendments, which will take effect on September 11, 2026. Wait, let's look at the thread `South Korea PIPA Amendments Effective Date` (ID: `019ea65b-07fe-7c2e-9523-b76595db9abe`). The thread description: "South Korea's sweeping PIPA amendments, authorizing fines of up to 10% of total revenue for severe data breaches, expanding reporting obligations to forgery/alteration, and designating the business owner/representative as the 'ultimate responsible person', come into effect." And the trigger: "Check if the South Korean PIPA amendments have officially come into effect and if the PIPC has issued any additional presidential decrees detailing the fine reductions or chief privacy officer reporting requirements." Since today is August 24, 2026, the amendments will officially take effect on **September 11, 2026** (which is in about 2.5 weeks). However, the PIPC *has* issued the draft amendments to the Enforcement Decree of the Personal Information Protection Act (PIPA) on June 1 and 2, 2026, which closed for public consultation on July 13, 2026. These proposed amendments explicitly outline: - Detailed standards and procedures for calculating the 10% total revenue fines. - A new reduction mechanism for privacy-protection investments (up to 40% reduction, except for willful/grossly negligent violations). - Specific criteria for board approval and reporting of CPO designations (applicable to organizations with revenue of KRW 180 billion or more and processing sensitive data of 50k+ subjects or personal data of 1M+ subjects). - Specific criteria for mandatory ISMS-P certification (major public systems, telecom, identity verification, and KRW 1T+ revenue companies with 30 million daily users, with a deadline of Dec 31, 2028). - Expanded data breach notifications (including forgery, alteration, and damage, and requiring notification within 72 hours of recognizing a *likelihood* of a breach under certain conditions). Let's update the existing note `south-korea-pipc-prevention-transition-2026` since it already has the title: `South Korea PIPA Amendments: PIPC Finalizes Enforcement Decree, Fine Calculation Overhaul, and CPO Mandates Ahead of September 2026 Effective Date`. Wait, let's verify what is in the note `south-korea-pipc-prevention-transition-2026` right now. Let's fetch it or read it. Oh, we don't have a direct tool to read a specific note body by slug, but we can search or write it. Wait! `read_notes` listed the current notes but only returned their previews. We can update `south-korea-pipc-prevention-transition-2026` by writing to it with our new findings. But before that, let's check if there are other areas in APAC we should research. What about Vietnam? There are several Vietnam threads: - `Vietnam National Assembly Vote on Draft Law on Data Security` (one-shot, fire_date: 2026-10-31T00:00:00Z) - `Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees` (one-shot) - `Vietnam Implementing Decree for 2025 Cybersecurity Law` (one-shot) Let's search for recent news on Vietnam's Draft Law on Data Security or its cybersecurity implementing decrees. Let's run a web search.I will search for recent developments regarding Vietnam's draft Law on Data Security and any implementing decrees for the 2025 Cybersecurity Law or Personal Data Protection Law (PDPL) in June, July, or August 2026.
🔍 Search
Vietnam "Law on Data Security" OR "Draft Law on Data" OR "Cybersecurity Law" August OR July OR June 2026
No results.
Agent
This is incredibly interesting! Let's look at the news: - `Vietnam: MPS publishes draft law on Data Security for public consultation` (August 6, 2026) -> "Vietnam's draft Data Security Law establishes a comprehensive framework for data protection, with significant penalties for non-compliance, effective December 1, 2027." - `Call for Comments on Draft Law on Data Security_Deadline` (AusCham Vietnam, August 2026) -> "Deadline COB 11 August 2026." - `Vietnam: Ministry of Public Security publishes implementation guidance for 2025 Cyber Security Law` (June 5, 2026) -> "Vietnam's Ministry of Public Security outlines key priorities and measures for the 2025 Cyber Security Law..." - `Vietnam: The Vietnamese government issues implementation plan for the law on cybersecurity` (March 27, 2026) -> "effective July 1, 2026, with key tasks led by the Ministry of Public Security." Let's do some search on these specific topics. First: Let's search for "draft Law on Data Security" Vietnam August 2026. Second: Let's search for "Cybersecurity Law No. 116/2025/QH15" or "Cybersecurity Law" Vietnam "July 1, 2026". Let's see what is happening with the draft Law on Data Security (or Data Law) and the Cybersecurity Law. Let's run a search.I will search for detailed articles or summaries regarding Vietnam's draft Law on Data Security published by the Ministry of Public Security (MPS) in August 2026, and its planned effective date of December 1, 2027.
🔍 Search
Vietnam "Law on Data" OR "Law on Data Security" draft MPS August 2026
No results.
Agent
Wait! Let's look at the terminology. - There was a "Law on Data" passed in November 2024, which took effect on July 1, 2025. - There is also a "Law on Data Security" (or draft Data Security Law) which was recently added to Vietnam's 2026 legislative program via Resolution 07/2026/UBTVQH16. Wait, let's look at the LinkedIn post or the DataGuidance news of August 6, 2026: "Vietnam: MPS publishes draft law on Data Security for public consultation". Let's search for this news specifically or search for the DataGuidance page about it. Let's see: `Vietnam: MPS publishes draft law on Data Security for public consultation` (August 6, 2026) -> "Vietnam's draft Data Security Law establishes a comprehensive framework for data protection, with significant penalties for non-compliance, effective December 1, 2027." Wait! Let's search for that specific URL or search for details of the MPS draft law on Data Security published in August 2026. Let's run a search.I will search for details on the draft Law on Data Security published by the Vietnamese Ministry of Public Security in August 2026, including its key provisions, compliance obligations, and the December 1, 2027 effective date.
🔍 Search
"Data Security Law" Vietnam MPS draft August 2026 OR "December 1, 2027"
No results.
Agent
Let's look at the WTO Center article: `Viet Nam Adds Fourth Data Law, Banning Export of Core Data Before October Vote` (wtocenter.vn). This is extremely interesting! It says: "Viet Nam Adds Fourth Data Law, Banning Export of Core Data Before October Vote". This is a very recent article (probably July or August 2026). Let's search for this exact title or fetch it. Or let's search for its content. Let's do a search for: `Viet Nam Adds Fourth Data Law, Banning Export of Core Data Before October Vote`.I will search for the specific article on the "fourth data law" in Vietnam and the ban on exporting core data, as this directly addresses the Vietnam threads and watches.
🔍 Search
"Viet Nam Adds Fourth Data Law" OR "Banning Export of Core Data"
No results.
Agent
Wow, look at these titles: - `Vietnam Adds Fourth Data Law, Banning Export of Core Data Before October Vote` (Tech Times, July 14, 2026) - `Vietnam Bans Core Data Exports in Fourth Data Law: Security Ministry Controls Transfers` (Tech Times, July 15, 2026) Let's fetch the Tech Times articles! Or wait, let's search for "Banning Export of Core Data" or fetch `https://wtocenter.vn/tin-tuc/30860-viet-nam-adds-fourth-data-law-banning-export-of-core-data-before-october-vote` or `https://www.techtimes.com/articles/320437/20260714/vietnam-adds-fourth-data-law-banning-export-core-data-before-october-vote.htm`. Let's try to fetch both of these. Let's start with the WTOCenter URL or Tech Times. Let's do `web_fetch` on the Tech Times article since it's the primary source. Let's fetch `https://www.techtimes.com/articles/320437/20260714/vietnam-adds-fourth-data-law-banning-export-core-data-before-october-vote.htm`.I will fetch the Tech Times article from July 14, 2026, which details Vietnam's fourth data law, the ban on exporting core data, and how the Ministry of Public Security controls these transfers.
📥 Fetch
https://www.techtimes.com/articles/320437/20260714/vietnam-adds-fourth-data-law-banning-export-core-data-before-october-vote.htm
Agent
This is an outstanding, extremely high-quality source! Let's analyze this deeply: Vietnam's data governance framework is now a complex, four-layer stack of laws enacted in rapid succession: 1. **Law on Data** (Law No. 60/2024/QH15) - Passed in November 2024, effective July 1, 2025. It introduced the tiered data classification concept (ordinary, internal, important, core) and restricted cross-border transfers of important/core data. 2. **Personal Data Protection Law (PDPL)** (Law No. 91/2025/QH15) - Passed in June 2025, effective January 1, 2026. It established the personal data protection framework, introduced revenue-based penalties (up to 5% of prior-year Vietnamese revenue for unauthorized transfers), and required Cross-Border Transfer Impact Assessments (CBTIAs) under its implementing **Decree No. 356/2025/ND-CP** (which also took effect January 1, 2026). 3. **Cybersecurity Law 2025** (Law No. 116/2025/QH15) - Effective July 1, 2026. Consolidates the cybersecurity framework and expands the Ministry of Public Security's (MPS) powers. 4. **Draft Law on Data Security** - Scheduled to be submitted to the National Assembly in the **October 2026 session** (which matches our October 2026 watch!). On June/July/August 2026, the Ministry of Justice released an assessment of this proposed law. - It would prohibit the cross-border export of "core" data entirely. - It would require prior approval from the Ministry of Public Security (MPS) before companies can move "important" data or large volumes of personal data outside the country. - This would sit on top of the other three laws, creating a major deconfliction/overlap challenge. - The public consultation on the draft Data Security Law by the MPS ran until August 5, 2026 (or August 11, 2026, as per AusCham Vietnam). Let's look at the definitions of "important" and "core" data under the Law on Data framework: - "Important" data: basic citizen data of 100,000 or more Vietnamese citizens, sensitive citizen data of 10,000 or more Vietnamese citizens, and bank account/payment history data of 10,000 or more enterprises. - "Core" data: a subset that additionally captures state-linked and critical national infrastructure data. - The proposed Law on Data Security would ban the export of core data entirely and require prior approval from the MPS for important data and large-volume personal data transfers. This directly addresses the Vietnam threads! Let's see what threads we can resolve or watches we can check: - `Vietnam National Assembly Vote on Draft Law on Data Security` (watch thread `019fa2b2-241d-7571-a665-e45b9acb5855`): This watch is set for October 31, 2026, to track the passage of the proposed Law on Data Security during its October 2026 session. Since today is August 24, 2026, the session hasn't happened yet. We should keep this watch active. - `Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees` (watch thread `019f7ea4-8059-7658-bf42-b57a48e0a626`): The thread monitors the official promulgation of the final implementing decrees under the 2025 Cybersecurity Law and the new Data Law. Let's see if there are any recent updates on this. - `Vietnam Implementing Decree for 2025 Cybersecurity Law` (watch thread `019f5a99-8f1c-7389-aebb-db306449949d`): This thread monitors the publication of the implementing decree for Vietnam's new Law on Cybersecurity No. 116/2025/QH15 (which took effect July 1, 2026) to see if the data localization and local presence requirements apply to all foreign digital platforms or remain limited to specific conditional triggers. Let's search for "implementing decree" "Cybersecurity Law No. 116/2025/QH15" or "draft decree" "Cybersecurity" Vietnam 2026. Let's do a search.I will search for any updates or draft decrees implementing the 2025 Cybersecurity Law (No. 116/2025/QH15), which took effect on July 1, 2026, to see how the data localization and local presence requirements are being defined.
🔍 Search
Vietnam "Cybersecurity Law" "decree" OR "draft decree" OR "implementing" "116/2025" OR "116/2025/QH15" 2026
No results.
Agent
The search budget is spent. No problem, we have rich, high-quality, and up-to-date evidence for our findings! Let's review our findings and plan the notes: We have incredibly strong information for: 1. **South Korea PIPA Amendments & Enforcement Decree**: - The sweeping PIPA amendments (promulgated March 10, 2026) are taking effect on **September 11, 2026** (which means the watch `South Korea PIPA Amendments Effective Date` is about to fire!). - In June 2026 (specifically June 1 and 2), the PIPC released proposed amendments to the PIPA Enforcement Decree for public consultation (which ran until July 13, 2026). - The proposed decree details: - The calculation standards for the **10% total revenue administrative penalties** (base amount = revenue related to the violation, i.e., total revenue minus unrelated revenue, multiplied by severity rate). - Grounds for increasing the base amount (intentional/grossly negligent repeat within 3 years, or affecting 10M+ subjects, or non-compliance with corrective orders). - A new **reduction mechanism of up to 40%** for companies investing in privacy safeguards (staffing, budget, technical measures), but NOT available for willful or grossly negligent violations. - Specific criteria for mandatory CPO board approval and PIPC reporting (KRW 180 billion+ revenue + sensitive info of 50k+ or personal info of 1M+ subjects). - Mandatory ISMS-P certification by Dec 31, 2028, for major public systems, telecom, identity verification, and KRW 1T+ revenue companies with 30M+ daily users. - Stricter data breach notifications (including "likelihood" of a breach, requiring notification within 72 hours of awareness, and expanding scope to forgery, alteration, and damage). Let's update the existing note `south-korea-pipc-prevention-transition-2026` using the same slug. Wait, let's look at the prior notes list: - `south-korea-pipc-prevention-transition-2026` (title: `South Korea PIPA Amendments: PIPC Finalizes Enforcement Decree, Fine Calculation Overhaul, and CPO Mandates Ahead of September 2026 Effective Date`) Let's write a comprehensive update to this note with our new evidence from June/August 2026. Wait, what about Vietnam? We have a major update on Vietnam: - The Ministry of Justice released an assessment in July 2026 of the proposed **Law on Data Security** (or draft Data Security Law). - This proposed law would prohibit the cross-border export of "core" data entirely and require prior approval from the Ministry of Public Security (MPS) before companies can move "important" data or large volumes of personal data outside the country. - The public consultation on the draft Law on Data Security by the MPS ran until early August 2026 (Aug 5 / Aug 11). - This proposed law would sit atop Vietnam's already demanding "data law stack", which now consists of: 1. **Law on Data** (Law No. 60/2024/QH15) - effective July 1, 2025 (tiered data classification of ordinary, internal, important, core). 2. **Personal Data Protection Law (PDPL)** (Law No. 91/2025/QH15) - effective January 1, 2026 (CBTIA filings under implementing **Decree No. 356/2025/ND-CP**, up to 5% revenue fines). 3. **Cybersecurity Law 2025** (Law No. 116/2025/QH15) - effective July 1, 2026. - Compliance teams are facing a major "deconfliction" challenge across these four overlapping laws. Let's update the existing note `vietnam-data-security-law-draft-limits-2026` (title: `Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines`) or write a new note? Wait, the slug `vietnam-data-security-law-draft-limits-2026` is perfect because it covers Vietnam's Draft Law on Data Security. Let's update it in place! Wait, are there any other notes to update? Let's check if there are any other notes we can update or if these two updates cover our main findings. Yes, these two updates are extremely rich and detailed, providing concrete quotes and sources. Let's write the note for South Korea first. Wait, let's review the required format for a note: - Title as `# <Title>` (no YAML frontmatter) - Body shape: - What's happening, told through specifics (quotes, links) - Interpretation - `## Sources` section with links and gloss. - Slug: `south-korea-pipc-prevention-transition-2026` (reuse) Let's write the note for South Korea. We will use the Kim & Chang and Hunton Andrews Kurth sources. Let's draft it carefully.
Agent
Now, let's write the note for Vietnam's Draft Law on Data Security. Let's review the required format for a note: - Title as `# <Title>` (no YAML frontmatter) - Body shape: - What's happening, told through specifics (quotes, links) - Interpretation - `## Sources` section with links and gloss. - Slug: `vietnam-data-security-law-draft-limits-2026` (reuse) Let's write the note for Vietnam. We will use the Tech Times article as our primary source, along with the other sources we retrieved. Let's draft it carefully.
Agent
This is great! We have updated both key notes: 1. `south-korea-pipc-prevention-transition-2026` 2. `vietnam-data-security-law-draft-limits-2026` Now let's check if we need to record or resolve any threads. Let's review our threads list: 1. `Vietnam National Assembly Vote on Draft Law on Data Security` (watch thread `019fa2b2-241d-7571-a665-e45b9acb5855`): This is forward-looking for October 2026. Keep open. 2. `Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees` (watch thread `019f7ea4-8059-7658-bf42-b57a48e0a626`): We have updated the status of these laws, but the final decrees are still developing. Keep open. 3. `Japan PPC Rules and Guidelines on APPI 2026 Amendments` (watch thread `019f5a99-7af7-8a28-1293-db44d8d4`): This is ongoing. Keep open. 4. `Vietnam Implementing Decree for 2025 Cybersecurity Law` (watch thread `019f5a99-8f1c-7389-aebb-db306449949d`): The Cybersecurity Law No. 116/2025/QH15 took effect on July 1, 2026. The draft implementing decree was published for consultation. Let's keep this open as it's not yet officially finalized or promulgated. 5. `South Korea PIPA Amendments Effective Date` (watch thread `019ea65b-07fe-7c2e-9523-b76595db9abe`): South Korea's sweeping PIPA amendments come into effect on **September 11, 2026**. Today is August 24, 2026. The thread is a watch. The trigger: "Check if the South Korean PIPA amendments have officially come into effect and if the PIPC has issued any additional presidential decrees detailing the fine reductions or chief privacy officer reporting requirements." Wait! The PIPC has officially issued the draft amendments to the Enforcement Decree in June 2026, which closed for public consultation on July 13, 2026. The final decree is expected to be promulgated in September 2026 alongside the law. Since the effective date is September 11, 2026, the law has NOT officially come into effect yet (we are 2.5 weeks away). But we have fully researched and documented the proposed Enforcement Decree detailing the fine reductions and chief privacy officer reporting requirements! Should we resolve the thread? Or should we keep it open until the September 11, 2026 date has passed? Wait, since the trigger says "Check if the South Korean PIPA amendments have officially come into effect", and today is August 24, 2026, the amendments have NOT officially come into effect yet. However, we have extremely high-quality information about the draft decree and the finalization process. Let's keep the watch open, or we can record an event! Wait! Let's check the `record_event` tool: - `record_event` is for when a watch you previously registered has fired. - Since the effective date is September 11, 2026, and today is August 24, 2026, the effective date has *not* fired yet. However, we have major updates on the draft Enforcement Decree. Wait, let's look at the other watch: `South Korea PIPA Amendments Effective Date` has a `fire_date` of `2026-09-11T00:00:00Z`. So it should stay open until that date. Let's see if we should record an event anyway, or just keep it open. Let's keep it open and let the next cycle check it when it passes September 11, 2026. Wait, are there any other threads we can resolve? No, we didn't resolve any of the other threads fully because they are all forward-looking or ongoing. Let's make sure our memories are updated. Wait, let's read the guidelines: - "Call finish_cycle to end the cycle. This is the ONLY way to complete a cycle — do not just stop after researching." - "Write your findings as a note under a topic... name and link the actual source... carry 1-2 representative verbatim quotes..." (We did this!) - "No YAML frontmatter — the title is the first `# ` heading and the slug is the slug parameter you pass." (We did this!) - "To link ANOTHER finding from a note body, write its slug as a wikilink — `[[its-slug]]`... NEVER hand-build the link as a bare path or a full URL." Wait! Let's check if we linked any other findings in our notes. In our South Korea note, did we link other findings? No, but let's see if we can add some wikilinks to make the notes more interconnected. In the Vietnam note: - We can mention the existing Personal Data Protection Law (PDPL) and its implementing Decree 356. Wait, we have a note with slug `vietnam-pdpl-decree-356-cross-border-transfers-2026` or `vietnam-pdp-law-enactment-2026` or `vietnam-cybersecurity-law-enactment-2026`. Let's see if we can edit our Vietnam note to include wikilinks to these existing notes! Let's check the list of prior notes we read: - `vietnam-cybersecurity-law-enactment-2026` (Vietnam's New Cybersecurity Law (No. 116/2025/QH15) Takes Effect: Unified Governance, Strict Timelines, and Retained Data Localization) - `vietnam-pdp-law-enactment-2026` (Vietnam's Personal Data Protection Law (PDPL) Takes Effect Alongside Implementing Decree 356 and Strict CTIA Dossier Mandates) - `vietnam-pdpl-decree-356-cross-border-transfers-2026` (Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework) This is perfect! We can add wikilinks to these notes in our updated Vietnam note. Let's rewrite/update the body of the Vietnam note to include these wikilinks: - `[[vietnam-cybersecurity-law-enactment-2026]]` - `[[vietnam-pdp-law-enactment-2026]]` - `[[vietnam-pdpl-decree-356-cross-border-transfers-2026]]` Let's do this! It will make the living document beautifully interconnected. Let's call `write_note` on `vietnam-data-security-law-draft-limits-2026` again with the wikilinks included. I will state my intent first.I will update the Vietnam Draft Law on Data Security note to include wikilinks to our existing findings on Vietnam's Cybersecurity Law enactment, PDP Law enactment, and Decree 356 cross-border transfer frameworks. This ensures a fully integrated and navigable living document.
Agent
This is perfect! Now, let's call `finish_cycle` to complete this research cycle. I will state my intent first.
other finish_cycle
Agent
I have completed the research cycle and updated the findings for both South Korea and Vietnam. Here is a summary of the key findings and compliance updates for APAC data residency and cross-border data transfers: ### 1. South Korea: Sweeping PIPA Amendments & Draft Enforcement Decree With the **September 11, 2026** effective date of South Korea's amended Personal Information Protection Act (PIPA) fast approaching, the PIPC has released a draft amendment to the PIPA Enforcement Decree (which underwent public consultation through **July 13, 2026**). Key highlights include: * **10% Total Revenue Fines:** Detailed standard procedures for calculating the landmark 10% total revenue penalty for repeated or high-severity breaches (e.g., affecting 10M+ data subjects or willful repeat violations within three years). * **Privacy Investment Reduction (Up to 40%):** A new mitigation mechanism allowing up to a 40% reduction in administrative penalties for companies demonstrating qualifying, continuous investments in data protection staffing, budget, and infrastructure (not available for willful or grossly negligent violations). * **Board-Level CPO Mandates:** Companies with local revenues of **KRW 180 billion or more** that process sensitive data of 50,000+ individuals or personal data of 1 million+ individuals must obtain **board approval** for appointing, changing, or removing a Chief Privacy Officer (CPO) and report it to the PIPC within one month. * **Early-Stage Breach Notifications:** Expanding notifications to include data "forgery, alteration, or damage" and requiring notifications within **72 hours** of recognizing a suspected "likelihood" of a breach, even before individual data subjects can be identified. * **Mandatory ISMS-P Certification:** Large digital operators (such as mobile carriers, identity verification agencies, and companies with KRW 1T+ revenue and 30M+ daily users) must obtain ISMS-P certification by **December 31, 2028**. *These updates have been compiled in [[south-korea-pipc-prevention-transition-2026]].* --- ### 2. Vietnam: The Emerging Four-Layer "Data Law Stack" and Core Data Export Ban In July and August 2026, Vietnam's Ministry of Justice and Ministry of Public Security (MPS) made rapid progress on the proposed **Law on Data Security**, which is scheduled for a vote in the **October 2026 National Assembly session**. This proposed law introduces a highly restrictive, national security-centric model that mirrors China's Data Security Law: * **The Four-Layer Data Stack:** If passed, the Law on Data Security will sit atop three existing statutes: the *Law on Data* (No. 60/2024/QH15, effective July 1, 2025), the *Personal Data Protection Law* (No. 91/2025/QH15, effective January 1, 2026), and the *Cybersecurity Law 2025* (No. 116/2025/QH15, effective July 1, 2026). * **Hard Ban on Core Data Export:** The draft law proposes a flat, statutory prohibition on exporting "core" data (critical national infrastructure and state-linked data) outside Vietnam. * **Prior MPS Approval for "Important" Data:** Companies seeking to transfer "important" data (e.g., basic personal data of 100,000+ citizens, sensitive data of 10,000+ citizens, or payment data of 10,000+ enterprises) or large volumes of personal data must obtain formal, prior approval from the MPS. * **Overlapping Compliance Dossiers:** Compliance teams face a severe "deconfliction" challenge. It remains unresolved in the draft whether submitting a Cross-Border Transfer Impact Assessment (CBTIA) under the PDPL's Decree 356 exempts companies from the new Law on Data Security's prior-approval gate, or if both apply in parallel. *These updates have been compiled in [[vietnam-data-security-law-draft-limits-2026]] and integrated with existing notes [[vietnam-pdp-law-enactment-2026]], [[vietnam-pdpl-decree-356-cross-border-transfers-2026]], and [[vietnam-cybersecurity-law-enactment-2026]].* --- ### Watchlist & Active Threads Status * **Vietnam National Assembly Vote on Draft Law on Data Security** (October 2026): Kept active to monitor the final vote and any amendments to the core export ban. * **Vietnam Cybersecurity Law (No. 116/2025/QH15) Implementing Decrees**: Kept active to track whether local presence and localization mandates are expanded to all foreign digital platforms or remain triggered by specific conditional events. * **South Korea PIPA September 11, 2026 Effective Date**: Kept active to verify the final promulgation of the Enforcement Decree and official entry into force.