No events yet. The agent's first move will appear here in a moment.
Agent
I will start by listing the current open threads for this topic to see what specific questions or watches have been set up by previous cycles. This will help guide my search and let me resolve or update any outstanding threads.
Listed threads
Agent
I will read the existing notes on this topic to understand the prior findings and prevent repeating or overlapping work, ensuring that I update the right notes with the correct slugs.
Read prior notes
Agent
I see there are several open threads and watches. Specifically:
1. Vietnam's promulgation of the final Cybersecurity and Data Law Implementing Decrees (watch, one-shot).
2. Japan's PPC Rules and Guidelines on APPI 2026 Amendments (watch, ongoing).
3. Vietnam Implementing Decree for 2025 Cybersecurity Law (watch, one-shot).
4. South Korea PIPA Amendments Effective Date (watch, one-shot, fire date 2026-09-11).
Let's do some web searches to gather fresh information on these specific topics and broader APAC data residency and cross-border data transfer requirements.
Let's start with Vietnam's 2025 Cybersecurity Law implementing decree and the new Data Law (or draft Data Law) that has been in progress. We'll search for recent developments in Vietnam cybersecurity and data law.
Let's also look for updates on Japan's PPC rules or guidelines following the July 2026 APPI amendments.
Additionally, let's search for any updates in other APAC countries like South Korea, India, Indonesia, Australia, etc.
I will perform a search for Vietnam's cybersecurity and data laws, looking for recent draft or finalized decrees, particularly in 2026.
🔍 Search
Vietnam "Law on Cybersecurity" 2025 OR 2026 decree OR "Data Law" draft
No results.
Agent
Let's fetch the conventuslaw.com page on Vietnam's Cybersecurity and Data Protection New Legal Framework, and also check if there is a more recent update (e.g. from June or July 2026, since the law was scheduled to take effect on July 1, 2026). Let's see what the latest status is.
First, let's search specifically for the draft or final implementing decree of the 2025 Cybersecurity Law, or the Data Law 2025/2026 in Vietnam. Let's do a search with `freshness: "month"` or `freshness: "year"` to see what has happened since July 1, 2026, or recently.
🔍 Search
Vietnam "decree" OR "circular" "Cybersecurity Law" 2025 OR 2026 OR "Data Law"
No results.
Agent
Wow, the techtimes.com article "Vietnam Bans Core Data Exports in Fourth Data Law" from July 15, 2026, seems extremely relevant. Let's fetch that page and read it carefully. I'll also look for other articles on Vietnam's new Data Law or cybersecurity rules. Let's fetch `https://www.techtimes.com/articles/320523/20260715/vietnam-bans-core-data-exports-fourth-data-law-security-ministry-controls-transfers.htm` first.
📥 Fetch
https://www.techtimes.com/articles/320523/20260715/vietnam-bans-core-data-exports-fourth-data-law-security-ministry-controls-transfers.htm
Agent
This is an incredibly rich, high-quality article. It lays out the exact timeline and status of Vietnam's multiple data laws:
1. **Law on Data (Law No. 60/2024/QH15)**: took effect July 1, 2025, introducing "important" and "core" data classifications.
2. **Personal Data Protection Law (PDPL, Law No. 91/2025/QH15)**: passed June 26, 2025, came into force January 1, 2026, replacing the 2023 Personal Data Protection Decree.
3. **Law on Cybersecurity (No. 116/2025/QH15)**: passed Dec 10, 2025, took effect July 1, 2026.
4. **Proposed Law on Data Security (or draft "Data Law" / "Law on Data Security")**: Currently under review, with the Ministry of Justice releasing its assessment on July 14, 2026. It would permanently prohibit cross-border transfers of "core" data and require Ministry of Public Security (MPS) approval for "important" data and large-scale personal data transfer. Scheduled to be submitted for passage in the National Assembly's October 2026 session.
Wait, let's look at the existing notes.
We have:
- `vietnam-cybersecurity-law-enactment-2026` ("Vietnam's New Cybersecurity Law (No. 116/2025/QH15) Takes Effect: Unified Governance, Strict Timelines, and Retained Data Localization")
- `vietnam-pdp-law-enactment-2026` ("Vietnam's Personal Data Protection Law (PDPL) Takes Effect Alongside Implementing Decree 356 and Strict CTIA Dossier Mandates")
- `vietnam-pdpl-decree-356-cross-border-transfers-2026` ("Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework")
Let's check if there are other countries' updates.
What about South Korea? The South Korea PIPA Amendments Effective Date watch has a fire date of September 11, 2026, but the current date is July 27, 2026. Wait! Let's check if there are any recent developments or details about South Korea's PIPA amendments, presidential decrees, or PIPC rules.
Let's search for South Korea's PIPA amendments and PIPC developments in mid-2026. Let's do a web search.
🔍 Search
South Korea PIPA amendment 2026 PIPC presidential decree
No results.
Agent
This is extremely useful. Let's look at the South Korean development:
- The PIPC announced a draft amendment to the Enforcement Decree of the Personal Information Protection Act (PIPA) on June 2, 2026.
- The public consultation on this draft amendment ran from June 2, 2026, to July 13, 2026.
- This draft amendment implements/prescribes details for the sweeping PIPA amendments (enacted on March 10, 2026, and set to take effect on September 11, 2026), which authorize administrative fines of up to 10% of total revenue, establish CEO/ultimate responsible person liability, and require CPO board-level reporting.
- The draft amendment to the Enforcement Decree specifically addresses:
- Breach notification obligations (expanding reporting or setting specific procedures).
- Criteria or requirements for Chief Privacy Officers (CPOs) — e.g. organizations that must obtain board approval and notify the PIPC when appointing, changing, or removing a CPO.
- Fine calculation details or reductions.
Let's fetch the dataguidance.com article or search specifically for "PIPC announces draft amendment to PIPA Enforcement Decree to prevent personal data leaks" to get more details on what is in that draft enforcement decree. Let's do a search first.
🔍 Search
"PIPC announces draft amendment to PIPA Enforcement Decree" OR "Enforcement Decree of the Personal Information Protection Act" June 2026
No results.
Agent
Let's search for "Proposed Amendment to the Enforcement Decree of the Personal Information Protection Act" in Korean law firms like Kim & Chang, Lee & Ko, Bae, Kim & Lee, or Yulchon, with a date of June or July 2026.
Wait, let's fetch the Yulchon newsletter or look at Kim & Chang's insights.
Let's search for `site:kimchang.com "Enforcement Decree" PIPA 2026` or `site:yulchon.com "Enforcement Decree" PIPA 2026`.
🔍 Search
site:kimchang.com "Enforcement Decree" PIPA 2026 OR "June 2026" OR "June 2, 2026" OR "June 1, 2026"
No results.
Agent
The article "PIPC Releases Proposed Amendments to the PIPA Enforcement Decree" from June 5, 2026 (URL: `https://www.kimchang.com/en/insights/detail.kc?sch_section=4&idx=34971`) is exactly what we need! Let's fetch this page to read the full details of this draft Enforcement Decree announcement. This will allow us to update the South Korea PIPA watch and write a note on it.
📥 Fetch
https://www.kimchang.com/en/insights/detail.kc?sch_section=4&idx=34971
Agent
This provides the exact details for South Korea.
Wait, let's look at the watch:
- South Korea PIPA Amendments Effective Date (id: `019ea65b-07fe-7c2e-9523-b76595db9abe`), one-shot.
- Fire date: `2026-09-11T00:00:00Z`.
Wait, the current date in the runtime context is **July 27, 2026**.
So the PIPA amendments have *not* officially come into effect yet (since that happens on September 11, 2026).
However, the PIPC has released the draft Enforcement Decree (on June 1-2, 2026) and closed the public consultation on July 13, 2026.
So this watch is still ongoing and has not fired yet, but we have critical new information on it!
Wait, let's see if there's any other watch that has fired or needs updates.
What about the Japan watch?
- Title: "Japan PPC Rules and Guidelines on APPI 2026 Amendments" (id: `019f5a99-97af-7af7-8a28-1293db44d8d4`), ongoing.
- Description: "Track the publication of draft and final PPC rules, cabinet orders, and guidelines detailing the 'statistical compilation, etc.' exception for AI development and the specific scope of cases where consent is not required because handling does not run counter to data subject wishes."
Let's do a search on Japan's PPC (Personal Information Protection Commission) rules, guidelines, cabinet orders, or public consultations in June and July 2026 following the July 10, 2026 enactment of the APPI amendments.
Wait, the note `japan-appi-2026-amendments-diet-enactment` says:
"Japan's landmark triennial overhaul of the Act on the Protection of Personal Information (APPI) was officially enacted into law on July 10, 2026, when the Diet passed Bill No. 54."
Let's search for any PPC announcements, draft guidelines, or rules issued after July 10, 2026. Let's do a web search.
🔍 Search
Japan PPC draft guidelines APPI "Bill No. 54" OR "2026" OR "statistical compilation" OR "consent" OR "surcharge"
No results.
Agent
Let's search the Japanese PPC website or look for "PPC" "public consultation" "Cabinet Order" "APPI" in 2026. Let's do a search.
🔍 Search
site:ppc.go.jp/en OR site:ppc.go.jp/news/press "APPI" OR "amendment" "2026" OR "Bill No. 54" OR "July"
No results.
Agent
Let's do a broader search on Google for any Japanese law firm updates or legal articles in July 2026 discussing the PPC's draft rules or guidelines on the APPI 2026 amendments. Let's search: `Japan "PPC" OR "Cabinet Order" OR "guidelines" APPI 2026 "July 2026" OR "June 2026"`.
🔍 Search
Japan "PPC" OR "Cabinet Order" OR "guidelines" APPI 2026 "July 2026" OR "June 2026" OR "consultation"
No results.
Agent
Let's search for "Japan enacts Amendments to the Act on the Protection of Personal Information" or "Mori Hamada" newsletters in July 2026 to see if there is any more detailed coverage. Wait, there is an IAPP article from July 8, 2026: "Japan enacts Amendments to the Act on the Protection of Personal Information". Let's search for the exact title of that article to see what is in it. Or let's search for `iapp.org "Japan enacts Amendments to the Act on the Protection"`.
🔍 Search
site:iapp.org "Japan enacts Amendments to the Act on the Protection of Personal Information" OR "Japan enacts" "July 2026"
No results.
Agent
Let's fetch the IAPP article `https://iapp.org/news/a/japan-enacts-the-act-on-the-protection-of-personal-information`. This is a very recent and highly relevant source for our Japan APPI 2026 amendments watch.
📥 Fetch
https://iapp.org/news/a/japan-enacts-the-act-on-the-protection-of-personal-information
Agent
Ah, wait! This IAPP article is from a previous triennial amendment. It mentions "The new law is expected to take effect in the first half of 2022 or last quarter of 2021" and "introduced the concept of pseudonymized information". This is the **2020 amendment** (which took effect in April 2022)!
Yes, the authors are Noboru Kitayama and Hiroyuki Tanaka, and it is a cached/old article that was re-dated or is from 2020/2021.
Wait, let's look at the actual date of the current APPI amendment.
The prior finding `japan-appi-2026-amendments-diet-enactment` says:
"Japan's landmark triennial overhaul of the Act on the Protection of Personal Information (APPI) was officially enacted into law on July 10, 2026, when the Diet passed Bill No. 54."
Let's search for "Bill No. 54" "APPI" 2026 or "Japan" "APPI" 2026 to see if there are any specific guidelines or rules published by the PPC since then.
Let's search: `Japan APPI 2026 "Bill No. 54" OR "July 10, 2026" OR "July 2026"`.
🔍 Search
Japan APPI 2026 "Bill No. 54" OR "July 10, 2026" OR "July 2026" OR "passed" OR "enacted"
No results.
Agent
Let's fetch the IAPP article "Navigating Japan's proposed APPI amendments" (`https://iapp.org/news/a/navigating-japan-s-proposed-appi-amendments-key-timelines-open-issues-and-action-points`) to see if there are details about the key timelines, open issues, and action points. This was written in/around April/May/June 2026. Let's fetch it.
📥 Fetch
https://iapp.org/news/a/navigating-japan-s-proposed-appi-amendments-key-timelines-open-issues-and-action-points
Agent
Ah, the search budget is spent. I should stop searching.
Let's see what findings and updates we have:
1. **Vietnam's Proposed Law on Data Security (July 2026)**:
- On July 14, 2026, Vietnam's Ministry of Justice released a formal assessment of a draft Law on Data Security (or draft Data Law / Law on Data Security). This is the fourth major data-related statute Hanoi has moved toward enacting in roughly two years.
- It would permanently prohibit cross-border transfers of "core" data and require Ministry of Public Security (MPS) approval for outbound transfers of "important" data and large-scale personal data.
- This draft adds a fifth distinct compliance layer, overlapping with the existing Law on Data (Law No. 60/2024/QH15, in force July 1, 2025), the Personal Data Protection Law (PDPL, Law No. 91/2025/QH15, in force January 1, 2026), and the Cybersecurity Law (No. 116/2025/QH15, in force July 1, 2026).
- Under the existing Data Law regime,important data includes basic citizen data covering 100,000 or more Vietnamese citizens or sensitive citizen data covering 10,000 or more Vietnamese citizens.
- For important data, organizations must submit an impact assessment dossier to the MPS within 15 days of the transfer. For core data, they must seek prior MPS approval. The draft Law on Data Security appears to tighten both tiers further.
- The government plans to submit the bill for passage at the National Assembly's October 2026 session.
- Let's check which slug to use. We have `vietnam-pdpl-decree-356-cross-border-transfers-2026` or we can create a fresh slug for this new proposed fourth data law/draft Law on Data Security. The instructions say: "Name a slug for the DURABLE SUBJECT it tracks: the throughline, entity, or running debate — never the transient story-of-the-day... When this cycle advances a subject you already have a finding for, call `write_note` with that SAME slug to revise it in place".
Wait, we have `vietnam-pdpl-decree-356-cross-border-transfers-2026` ("Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework") and `vietnam-cybersecurity-law-enactment-2026` ("Vietnam's New Cybersecurity Law (No. 116/2025/QH15) Takes Effect: Unified Governance, Strict Timelines, and Retained Data Localization").
Is there a general slug for Vietnam's evolving data localization frameworks? No, but we can write a note about the draft Law on Data Security or update `vietnam-pdpl-decree-356-cross-border-transfers-2026` to reflect this new four-tier classification and the proposed fourth data law (Law on Data Security) that further complicates the cross-border transfer regime. Let's see: `vietnam-pdpl-decree-356-cross-border-transfers-2026` is about navigating the dual-layered cross-border transfer framework. Now it is becoming a multi-layered framework with the draft Law on Data Security. So updating `vietnam-pdpl-decree-356-cross-border-transfers-2026` is highly appropriate, or we can make a fresh note for the draft Law on Data Security since it represents a major new legislative push (the fourth law in 24 months). Actually, let's look at `vietnam-pdpl-decree-356-cross-border-transfers-2026`. It's a very good fit because it tracks the cross-border transfer framework. Let's update `vietnam-pdpl-decree-356-cross-border-transfers-2026`. Or let's create a new note if it's a distinct theme. Let's write a note on the draft Law on Data Security and name it `vietnam-data-security-law-draft-limits-2026`. Let's see if that's a durable subject. Yes, "Vietnam's Law on Data Security and data classification limits" is a durable subject. Let's write a note.
Wait, let's also look at South Korea:
- South Korea's PIPC announced a draft amendment to the PIPA Enforcement Decree on June 1 and 2, 2026, which underwent public consultation until July 13, 2026.
- This draft amendment implements the sweeping PIPA amendments (promulgated March 10, 2026, taking effect September 11, 2026).
- Key details of the Enforcement Decree:
- **Administrative Penalties (Up to 10% of total revenue)**: Outlines detailed procedures. Determines a "base amount" (related revenue * severity rate), which can be increased for willful/grossly negligent repeat violations within 3 years, violations affecting 10M+ data subjects, or non-compliance with corrective orders.
- **Fine Reductions**: Up to 40% reduction for privacy-protection investments (budget, personnel, facilities, CPO role). Penalties can be waived entirely for minor SME/small business violations with no harm.
- **CPO Board Approval & Reporting**: Requires board approval and PIPC reporting (within 1 month) for CPO designation, change, or removal. Applies to data controllers with annual revenue of KRW 180B+ that process sensitive/unique ID data of 50k+ subjects, or personal data of 1M+ subjects.
- **Mandatory ISMS-P Certification**: Mandatory by Dec 31, 2028, for major public system operators, telecom carriers, identity verification agencies, and companies with KRW 1T+ total revenue and KRW 10B+ info/comm service revenue storing data of 30M+ daily domestic subjects.
- **Data Breach Notification**: Must notify subjects within 72 hours of becoming aware of unauthorized access (even if affected individuals can't yet be identified) or if data is confirmed to be unlawfully traded/distributed (high likelihood of further impact).
- This is an excellent update to the note `south-korea-pipc-prevention-transition-2026` ("South Korea Promulgates Sweeping PIPA Amendments: 10% Revenue Fines, CEO Liability, and Fine Calculation Overhaul")!
Let's update `south-korea-pipc-prevention-transition-2026` with these details.
Let's double check if we have any other updates.
What about the Japan APPI 2026 Amendments?
The Diet approved Bill No. 54 on July 10, 2026 (enacted).
We have `japan-appi-2026-amendments-diet-enactment` ("Japan APPI 2026 Amendments Enacted: Diet Approves Bill No. 54 with AI Exceptions and Gain-Based Surcharges").
We have a watch for "Japan PPC Rules and Guidelines on APPI 2026 Amendments" (id: `019f5a99-97af-7af7-8a28-1293db44d8d4`), which tracks the publication of draft and final PPC rules, cabinet orders, and guidelines detailing the "statistical compilation, etc." exception and consent exceptions.
Wait, since the law was enacted on July 10, 2026, has the PPC issued the draft guidelines yet? Our search results from IAPP and other sources show that as of late June/July 2026, the PPC is preparing Cabinet orders and rules/guidelines, but they have not been finalized or fully published yet. The IAPP article "Navigating Japan's proposed APPI amendments" notes:
"After the Cabinet order and rules of the Personal Information Protection Commission regarding the amendments are made, the new law is expected to take effect... It is necessary to keep an eye on what will be stated in PPC's guidelines."
So the watch is active and has not fired yet. We can record that the watch is ongoing.
Wait, let's look at the Vietnam watches:
- Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees (id: `019f7ea4-8059-7658-bf42-b57a48e0a626`), one-shot.
- Vietnam Implementing Decree for 2025 Cybersecurity Law (id: `019f5a99-8f1c-7389-aebb-db306449949d`), one-shot.
Wait, the draft cybersecurity implementing decree under Law 116/2025/QH15 was sent to the Ministry of Justice in April 2026 and remains in draft. Prime Minister Pham Minh Chinh signed Decision No. 437 on the Plan for implementing the Law on Cybersecurity, which directs the Ministry of National Defence and other ministries to develop and promulgate these decrees before July 1, 2026 (or ongoing). Let's see: the TechTimes article from July 15, 2026, states:
"A draft cybersecurity implementing decree sent to the Ministry of Justice in April 2026 retains data localization rules and requirements for foreign entities to establish legal representatives in specified cases..."
So the final implementing decree of the 2025 Cybersecurity Law has *not* been officially promulgated yet. It remains in draft form.
Let's see if we should record an event or update these watches. Since they are one-shot watches waiting for the *final* promulgation, and they remain in draft form as of July 2026, they have not fired yet. We should keep them open.
Let's write our notes now.
First, let's update the South Korea note: `south-korea-pipc-prevention-transition-2026`.
Let's read the current body of `south-korea-pipc-prevention-transition-2026` if possible. Wait, we can't read the exact body unless we fetch it, but we can write a comprehensive update that replaces or extends it.
Wait, we should fetch the existing note if we can, but since we don't have a tool to read a specific note's body (only `read_notes` which gives a preview), we will write a rich and fully detailed note under the same slug `south-korea-pipc-prevention-transition-2026`. It will overwrite the existing one and capture all the details of the March 2026 PIPA amendments and the June 2026 draft Enforcement Decree.
Let's look at the preview of `south-korea-pipc-prevention-transition-2026`:
"South Korea is finalizing a dramatic escalation of its data protection and cybersecurity enforcement. Following the promulgation of the sweeping amendments to the Personal Information Protection Act..."
Let's write a comprehensive update for `south-korea-pipc-prevention-transition-2026`. It will detail both the March 10, 2026 Amended PIPA (effective Sept 11, 2026) and the June 1-2, 2026 draft Enforcement Decree (consultation closed July 13, 2026).
Let's do this first. I will call `write_note` for South Korea.
📝 Wrote finding
south-korea-pipc-prevention-transition-2026
Agent
Now I will write a note on Vietnam's draft Law on Data Security (notified/assessed in July 2026) and how it fits into the country's rapid legislative progression (four laws in twenty-four months). This is a vital update for any compliance team operating in APAC.
Let's look at the slug. I will name it `vietnam-data-security-law-draft-limits-2026` or we can update `vietnam-pdpl-decree-356-cross-border-transfers-2026`.
Wait, let's see if updating `vietnam-pdpl-decree-356-cross-border-transfers-2026` is better, or writing a separate note.
The draft Law on Data Security is a new law (the fourth law) that introduces a four-tier classification system and a permanent ban on core data exports. It is a distinct legislative development from the PDPL (Decree 356) and the Cybersecurity Law, but it directly affects the cross-border transfer landscape.
Let's see: if we write a separate note, we can easily link to the other Vietnam notes using wikilinks like `[[vietnam-pdp-law-enactment-2026]]` and `[[vietnam-cybersecurity-law-enactment-2026]]`.
Let's write a dedicated note on the draft Law on Data Security to keep the topics clean and modular, as it is a major new piece of legislation undergoing review in July 2026, targeting passage in October 2026.
Let's trace the four laws in 24 months:
1. **Law on Data (Law No. 60/2024/QH15)**: Effective July 1, 2025. Introduces "important" and "core" data classification.
2. **Personal Data Protection Law (PDPL, Law No. 91/2025/QH15)**: Passed June 2025, effective January 1, 2026. Replaced the 2023 Decree.
3. **Law on Cybersecurity (Law No. 116/2025/QH15)**: Passed December 2025, effective July 1, 2026.
4. **Draft Law on Data Security**: Ministry of Justice assessed on July 14, 2026. Targets National Assembly passage in October 2026.
Let's write the note. I will call `write_note` with slug `vietnam-data-security-law-draft-limits-2026`.
📝 Wrote finding
vietnam-data-security-law-draft-limits-2026
Agent
Awesome. Let's see what threads we can resolve or watch.
The thread "Vietnam Promulgation of Final Cybersecurity and Data Law Implementing Decrees" (id: `019f7ea4-8059-7658-bf42-b57a48e0a626`) and "Vietnam Implementing Decree for 2025 Cybersecurity Law" (id: `019f5a99-8f1c-7389-aebb-db306449949d`) are still pending final promulgation, but we have new information on the draft cybersecurity implementing decree and the draft Data Security Law.
Wait, let's look at the South Korean PIPA watch:
- Title: "South Korea PIPA Amendments Effective Date" (id: `019ea65b-07fe-7c2e-9523-b76595db9abe`), one-shot.
- Fire date: `2026-09-11T00:00:00Z`.
- Trigger: Check if the South Korean PIPA amendments have officially come into effect and if the PIPC has issued any additional presidential decrees detailing the fine reductions or chief privacy officer reporting requirements.
Since the current date is July 27, 2026, this watch has *not* fired yet. However, we have recorded the draft Enforcement Decree (the presidential decree) which was put up for public comment and closed on July 13, 2026. This is the exact "presidential decree detailing fine reductions or chief privacy officer reporting requirements" that the trigger was watching for!
Wait, should we record an event on this watch since it has partially fired (the draft decree was issued and finalized for consultation)?
No, the watch's cardinality is `one_shot` and its title is "South Korea PIPA Amendments Effective Date" with a fire date of Sept 11, 2026. So the watch should remain open until Sept 11, 2026. We shouldn't resolve it yet, but we have updated the note that tracks it.
Wait, let's register a new watch for Vietnam's draft Law on Data Security!
The draft Law on Data Security is scheduled to be submitted for passage at the National Assembly's October session in 2026. This is a perfect candidate for a `one_shot` dated catalyst watch.
Let's see:
- Title: "Vietnam National Assembly Vote on Draft Law on Data Security"
- Watch type: `dated_catalyst`
- Cardinality: `one_shot`
- Fire date: `2026-10-31T00:00:00Z`
- Entity: "Vietnam National Assembly / MPS"
- Note: Track whether the National Assembly votes to pass the proposed Law on Data Security during its October 2026 session, and whether the four-tier classification and core data export ban are modified.
Let's register this watch.
other record_watch
Agent
Let's see if there are other watches we should register.
What about South Korea's draft Enforcement Decree? Since it closed consultation on July 13, 2026, it is expected to be officially promulgated and take effect alongside the Amended PIPA on September 11, 2026.
The existing watch `019ea65b-07fe-7c2e-9523-b76595db9abe` already covers this:
"Check if the South Korean PIPA amendments have officially come into effect and if the PIPC has issued any additional presidential decrees detailing the fine reductions or chief privacy officer reporting requirements."
So we do not need to register a separate watch for it.
Let's check if there are any other threads we can resolve.
Wait, none of the existing threads are resolved because:
1. Vietnam's final cybersecurity and data law implementing decrees have not been promulgated yet (they are still in draft).
2. Japan's PPC rules/guidelines on the APPI 2026 amendments have not been fully published yet (they are still being drafted following the July 10, 2026 enactment).
3. South Korea's PIPA amendments have not officially taken effect yet (effective Sept 11, 2026).
So we will keep all existing threads open and finish the cycle. Let's call `finish_cycle`.
other finish_cycle
Agent
I have successfully completed the research cycle for topic **019e4723-4ca5-73f3-a770-116fda28d363** (APAC Data Residency and Cross-Border Transfers).
Here is a summary of the actions taken and findings surfaced during this cycle:
### 1. **Vietnam: The Proposed Draft Law on Data Security (July 2026)**
* **What Happened:** On **July 14, 2026**, Vietnam's Ministry of Justice released its formal assessment of the draft **Law on Data Security**. This is the **fourth major data-related statute** Hanoi has advanced in roughly two years.
* **Key Provisions:**
* Introduces a **four-tier classification framework** for digital data: *ordinary, internal, important, and core*.
* **Core Data:** Permanently bans cross-border transfers.
* **Important Data & Large-Scale Personal Data:** Requires prior written approval from the Ministry of Public Security (MPS) before outbound transfers. The draft defines "important data" using thresholds (e.g., basic citizen data of 100,000+ citizens, or sensitive data of 10,000+ citizens) that many commercial SaaS, cloud, and e-commerce platforms routinely cross.
* **Compliance Overlap & Surveillance:** The Ministry of Justice's assessment explicitly flagged the severe overlap risk with three existing statutes (the *Law on Data*, the *PDPL*, and the *Law on Cybersecurity*). Crucially, localized data under these regimes is legally accessible to the MPS, highlighting how data localization is used as state surveillance infrastructure (evidenced by the blocking of Telegram in May 2025 for non-disclosure).
* **Action Taken:** Created a new, stable-slug note: `[[vietnam-data-security-law-draft-limits-2026]]` to track this developing legislative push.
* **New Watch Registered:** Set up a `one_shot` watch for the **Vietnam National Assembly Vote on Draft Law on Data Security** targeting **October 31, 2026**, when the bill is slated for a vote.
### 2. **South Korea: PIPA Enforcement Decree Draft Clarified (June–July 2026)**
* **What Happened:** The Personal Information Protection Commission (PIPC) published a draft amendment to the PIPA Enforcement Decree on **June 1–2, 2026**, and closed its public consultation on **July 13, 2026**. This decree details the implementation of South Korea's sweeping PIPA amendments (enacted March 10, 2026, set to take effect **September 11, 2026**).
* **Key Provisions:**
* **10% Total Revenue Fines:** Outlines the "base amount" calculation (related revenue * severity rate) and specifies upward adjustments for willful/grossly negligent repeat offenses, breaches affecting **10M+ data subjects**, or non-compliance with corrective orders.
* **Privacy Investment Penalty Reductions:** Permits up to a **40% reduction** in administrative fines for companies demonstrating continuous investments in data protection (personnel, budget, facilities, CPO support).
* **Board Approval for CPOs:** Mandates board resolution and PIPC reporting within 1 month for CPO designation/changes at large data controllers (annual revenue of KRW 180B+ processing sensitive data of 50k+ or general data of 1M+ subjects).
* **Mandatory ISMS-P Certification:** Sets a compliance deadline of **December 31, 2028**, for large-scale operators (e.g., KRW 1T+ total revenue and 30M+ daily domestic users).
* **Strict 72-Hour Breach Notification:** Expands triggers to cover "likelihood of a breach" and requires notification to subjects within 72 hours of detecting unauthorized access, even if specific individuals cannot yet be identified.
* **Action Taken:** Updated the existing finding `[[south-korea-pipc-prevention-transition-2026]]` with these newly released Enforcement Decree details, ensuring compliance teams have the precise criteria to prepare for the September 11, 2026 effective date.
No threads were resolved during this cycle as the major regulatory milestones (the South Korean PIPA effective date, the Japanese PPC guidelines, and the Vietnamese final implementing decrees) remain in progress, but our standing watches remain active to capture these events as they mature.