Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines

Updated

Vietnam's Draft Law on Data Security: MPS Moves Forward with Sector-Based Localization, Multi-Tier Classification, and Global Revenue Fines

Vietnam's Ministry of Justice released an assessment in July 2026 of a proposed Law on Data Security that would prohibit the cross-border export of "core" data entirely and require prior approval from the Ministry of Public Security (MPS) before companies can move "important" data or large volumes of personal data outside the country. This proposal, scheduled to be submitted to the National Assembly for a vote in the October 2026 session, adds a fourth statutory layer to Vietnam's already demanding data governance architecture and places foreign companies on the wrong side of an MPS approval gate before any data leaves the country.

The public consultation on this draft law, led by the Ministry of Public Security, concluded in early August 2026 (with deadlines on August 5 and August 11, 2026).

1. Vietnam's Four-Layer Data Law Stack

To understand what the proposed Law on Data Security adds, it is critical to map the four primary data laws that now govern the Vietnamese digital market:

  1. Law on Data (Law No. 60/2024/QH15) — Effective July 1, 2025. This law was the first to introduce the tiered data classification concept, distinguishing "important" and "core" data categories and restricting their cross-border transfer based on national defense and security considerations.
  2. Personal Data Protection Law (PDPL) (Law No. 91/2025/QH15) — Passed in June 2025 and effective January 1, 2026. This statute established the personal data protection framework proper, introducing revenue-based penalties (up to 5% of prior-year Vietnamese revenue for unauthorized transfers) and requiring Cross-Border Transfer Impact Assessments (CBTIAs) under its implementing Decree No. 356/2025/ND-CP (which also took effect January 1, 2026). See Vietnam's Personal Data Protection Law (PDPL) Takes Effect Alongside Implementing Decree 356 and Strict CTIA Dossier Mandates and Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework for more details.
  3. Cybersecurity Law 2025 (Law No. 116/2025/QH15) — Effective July 1, 2026. This consolidated Vietnam's cybersecurity framework and expanded the powers of the Ministry of Public Security (MPS). See Vietnam's New Cybersecurity Law (No. 116/2025/QH15) Takes Effect: Unified Governance, Strict Timelines, and Retained Data Localization.
  4. Draft Law on Data Security — Targeting passage in the October 2026 session. It sits atop the existing stack, introducing a hard export ban on "core" data and a formal MPS prior-approval requirement for "important" data and large-volume personal data transfers.
2. Triggers for the Core Data Ban and Important Data Approval

The four-tier classification system—ordinary, internal, important, and core—determines which data a company can freely transfer, which it must assess, which it must obtain approval for, and which it simply cannot move at all. Under the existing framework:

  • "Important" data is defined by volume thresholds and impact risk, including the basic personal data of 100,000 or more Vietnamese citizens, the sensitive personal data of 10,000 or more Vietnamese citizens, and the bank account and payment history data of 10,000 or more enterprises.
  • "Core" data is a subset of important data that additionally captures state-linked data and critical national infrastructure data.

The proposed Law on Data Security's major innovation is the addition of a formal statutory ban on exporting core data and a formal approval mechanism for important data:

"The proposed Law on Data Security's innovation is not the classification itself, which already exists under the Law on Data. It is the addition of a formal statutory ban on exporting core data and a formal approval mechanism for important data — requirements that would exist in parallel to, and above, the CBTIA regime already established under the PDPL."

3. Deconfliction and Overlap: The Core Operational Challenge

The primary challenge for multinational companies is navigating the overlap between these four overlapping statutes. Currently, companies routing Vietnamese user data to Singapore or the US for analytics, HR processing, or shared services are subject to the CBTIA filing requirement under PDPL Decree 356. Under Decree 356, companies have 60 days from the date of the first transfer to file a highly detailed dossier with the MPS, documenting the purpose, scope, offshore storage location, and recipient security measures.

If the proposed Law on Data Security passes in October 2026, companies will face a parallel approval gate:

"Reviewers of the draft outline have already flagged the risk of overlap and called for harmonization with existing frameworks... companies will need to know whether submitting a CBTIA under the PDPL exempts them from a separate approval filing under the new Law on Data Security, or whether both apply. That question has not yet been resolved in the draft."

4. A National Security-Centric Model

Unlike Western data protection frameworks modeled on the EU's GDPR, which rely on independent supervisory authorities, Vietnam's architecture places the Ministry of Public Security (MPS) at the center of all data governance, audit, and approval processes. This national security-centric data sovereignty model1 closely mirrors China's Data Security Law and Personal Information Protection Law (PIPL) structure:

"This design mirrors China's data governance structure more closely than it mirrors the EU's General Data Protection Regulation. China's Data Security Law and Personal Information Protection Law also use a four-tier classification model, also restrict cross-border transfers of 'important' data through a security assessment mechanism, and also vest approval authority in state security apparatus rather than an independent privacy regulator."

Vietnam has demonstrated that it is willing to enforce these rules aggressively. For example, in May 2025, the government blocked Telegram nationwide after the platform failed to comply with data-sharing requests.

Actionable Next Steps for Compliance Teams

With the National Assembly vote targeted for October 2026, compliance teams managing APAC operations must:

  1. Map and Classify Data Flows: Conduct data classification audits to identify whether any local data flows meet the "important" or "core" classification thresholds (e.g., sensitive data of 10,000+ citizens or basic data of 100,000+ citizens).
  2. Review CBTIA Filings: Ensure that current cross-border transfers are covered by CBTIA dossiers under PDPL Decree 356, as the MPS actively enforces these requirements with fines of up to 5% of local revenue. See Vietnam’s Decree 356/2025/ND-CP and Decree 165/2025/ND-CP: Navigating the Dual-Layered Cross-Border Data Transfer Framework for a detailed breakdown of these dossiers.
  3. Monitor the October 2026 Vote: Track whether the National Assembly passes the proposed Law on Data Security and how the deconfliction of overlapping approval processes is resolved in the final text.

  1. An instance of National security mandates are displacing consumer privacy as the primary driver of data controls. — Vietnam's upcoming framework establishes a national security-centric model of data sovereignty, vesting supreme oversight in the state's security apparatus rather than an independent privacy agency. ↩︎

Part of

This finding is an example of a pattern recurring across your work:

Revision history

  • Add wikilinks to existing Vietnam-related notes to integrate our findings into a beautifully interconnected living document.
    · by the agent
  • Update the Vietnam draft Law on Data Security note with the major developments from July and August 2026, including the Ministry of Justice assessment, the public consultation details, the four-layer data law stack, and the October 2026 National Assembly session timeline.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updated without a stated reason.
    · by the agent
  • Updating Vietnam Data Security Law draft with the newly revealed 4-tier data classification, core data export ban, and global revenue-based fines of up to 5%.
    · by the agent
  • Update the Vietnam draft Law on Data Security note with the specific 5% global revenue fine proposal, the upcoming August 5, 2026 consultation deadline, and the parallel March 2026 Draft Decree on Administrative Penalties, creating a comprehensive overview of Vietnam's four-layered data law stack and penalty framework.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent
  • Create a new note tracking the newly assessed draft Law on Data Security in Vietnam, detailing its four-tier data classification, transfer bans, and its overlap with existing statutes.
    · by the agent