Vietnam - Cybersecurity Regulation (24/2018/QH14)
Cybersecurity Law
Luật An ninh mạng
Vietnam
RAI-VN-NA-CYBERSE-2018Vietnam's foundational cybersecurity legislation establishing data localization requirements, security obligations for online service providers, and government oversight of cyberspace. The law requires certain data to be stored locally in Vietnam for at least 24 months and mandates cooperation with authorities on cybersecurity matters.
Summary
Law No. 24/2018/QH14 on Cybersecurity was passed by the National Assembly on June 12, 2018, and came into effect on January 1, 2019. This comprehensive legislation establishes Vietnam's foundational framework for protecting national cybersecurity while regulating online services and data management.
The law is notable for its controversial data localization provisions under Article 26.3, which require domestic and foreign companies providing certain online services in Vietnam to store specified categories of data locally. This includes personal data of Vietnamese service users, which must be stored in Vietnam for a minimum of 24 months from the date authorities request such storage. The regulatory period commences from the date enterprises receive a request from the authority until the ending time mentioned in the request.
The law shares similarities with China's Cybersecurity Law enacted in 2017, focusing on providing the government with the ability to control the flow of information. This approach differs from cybersecurity laws in other jurisdictions that were inspired by the EU's GDPR framework.
Implementing decrees, particularly Decree 53/2022/ND-CP and Decree 13/2023/ND-CP on personal data protection, provide further guidance on data localization requirements. These decrees clarify the scope and application of the data storage obligations.
The law covers a wide range of cybersecurity activities including protecting national information systems, ensuring security of critical infrastructure, preventing cyber attacks, and regulating content on cyberspace. It establishes obligations for both domestic and foreign service providers operating in Vietnam.
The cybersecurity framework has significant implications for AI systems that process Vietnamese user data, as such systems must comply with data localization requirements and security standards. This makes the Cybersecurity Law an essential component of Vietnam's emerging AI regulatory landscape, complementing newer legislation like the Law on Digital Technology Industry.
Vietnam has also passed Law No. 60/2024/QH15 on Data, which regulates data processing more broadly and introduces concepts like "digital data," "important data," and "core data," scheduled to take effect on July 1, 2025.
Full article
Read full text ↗Overview
Law No. 24/2018/QH14 on Cybersecurity was passed by Vietnam's National Assembly on June 12, 2018, and came into effect on January 1, 2019. This foundational legislation establishes Vietnam's comprehensive framework for protecting national cybersecurity while regulating online services and data management. The law is notable for its data localization provisions requiring certain data to be stored locally in Vietnam, drawing comparisons to China's 2017 Cybersecurity Law rather than the EU's GDPR approach. The law applies to both domestic and foreign entities providing online services in Vietnam.
Definitions
The law defines Cybersecurity as ensuring activities in cyberspace do not harm national security, social order and safety, or the legitimate rights and interests of agencies, organizations, and individuals. Cyberspace encompasses the network of interconnected computer systems and telecommunications networks. Important national security information systems include systems managed by Party agencies, state agencies, and critical national infrastructure. Data localization refers to requirements for storing specified categories of data on servers physically located within Vietnam's territory. Service providers include platforms offering telecommunications, e-commerce, social media, and other online services.
Governance and Institutional Framework
The Ministry of Public Security (MPS) serves as the primary authority for cybersecurity enforcement and oversight. The Ministry of Information and Communications (MIC) handles telecommunications and network security aspects. The Ministry of National Defense oversees cybersecurity related to defense systems. The law establishes coordination mechanisms among ministries and provincial authorities for cybersecurity incident response. Specialized cybersecurity forces operate under the direction of competent authorities to protect national information systems and respond to cyber threats.
Key Focus Areas
- Data Localization: Requires storage of Vietnamese user data locally for minimum 24 months upon authority request.
- National Information Systems Protection: Establishes security requirements for critical national infrastructure and government systems.
- Service Provider Obligations: Mandates domestic and foreign online service providers comply with Vietnamese cybersecurity requirements.
- Content Regulation: Prohibits content threatening national security, social order, or violating laws.
- Cyber Attack Prevention: Establishes mechanisms for detecting, preventing, and responding to cyber attacks.
- Personal Data Protection: Requires protection of personal data processed through online services.
- Cross-Border Data Transfers: Regulates transfer of data outside Vietnam with security requirements.
- Authentication Requirements: Mandates identity verification for certain online services.
- Incident Response: Establishes procedures for reporting and responding to cybersecurity incidents.
- Law Enforcement Cooperation: Requires service providers to cooperate with authorities on cybersecurity matters.
- Technical Standards: Sets security standards for information systems and networks.
- Critical Infrastructure Security: Protects essential services including energy, finance, transportation, and telecommunications.
Implementation Framework
The law took effect January 1, 2019, with implementation guided by subsequent decrees. Decree 53/2022/ND-CP provides detailed guidance on data localization requirements, clarifying which services and data types are subject to local storage obligations. Decree 13/2023/ND-CP on Personal Data Protection establishes additional requirements for personal data processing. Implementation includes establishing technical standards, enforcement mechanisms, and coordination among agencies. Service providers must implement security measures and establish procedures for responding to authority requests.
Monitoring and Evaluation
The Ministry of Public Security monitors compliance with cybersecurity requirements through inspections and audits. Service providers are required to submit periodic reports on their cybersecurity status and incident response activities. The law authorizes authorities to conduct inspections of information systems and request access to data for security purposes. Cybersecurity incident reporting is mandatory for significant threats to national security or public order. The government maintains databases tracking registered online services and their compliance status. International cooperation mechanisms support information sharing on cross-border cyber threats.
Penalties, Liability, and Appeals
The law establishes administrative penalties for violations including warnings, fines, and suspension of services. Fines can reach hundreds of millions of Vietnamese dong for serious violations. Criminal liability applies for cybersecurity offenses causing significant harm to national security or public order. Service providers bear liability for failures to implement required security measures or comply with authority requests. Repeat violations may result in permanent revocation of operating licenses. Administrative appeals may be filed with competent authorities, with judicial review available for disputed decisions. The law provides immunity for good faith cooperation with authorities on cybersecurity matters.
Relationship to Other Instruments
The Cybersecurity Law operates alongside the Network Information Security Law (2015) which focuses on technical security aspects. It complements the Law on Information Technology and Law on Electronic Transactions. Decree 13/2023/ND-CP (PDPD) provides the primary framework for personal data protection. The newly enacted Law on Digital Technology Industry (2025) builds upon cybersecurity foundations for AI governance. Law No. 60/2024/QH15 on Data (effective July 2025) will introduce additional data governance requirements.
International Alignment
Vietnam's Cybersecurity Law adopts a sovereignty-focused approach to data governance, similar to China's 2017 Cybersecurity Law, rather than the rights-based approach of the EU's GDPR. The data localization requirements reflect Vietnam's policy of maintaining control over data concerning Vietnamese citizens. The law supports Vietnam's participation in ASEAN cybersecurity cooperation frameworks while maintaining national regulatory authority. International businesses operating in Vietnam must adapt to these requirements, which differ significantly from Western data protection models. The approach prioritizes national security and government access to data over cross-border data flow facilitation.
Implementation Timeline
| Date | Milestone |
|---|---|
| 2018-06-12 | Law No. 24/2018/QH14 passed by National Assembly |
| 2019-01-01 | Cybersecurity Law enters into force |
| 2022-08-15 | Decree 53/2022/ND-CP issued (data localization guidance) |
| 2023-04-17 | Decree 13/2023/ND-CP issued (personal data protection) |
| 2024-11-29 | Law on Data (No. 60/2024/QH15) enacted |
| 2025-07-01 | Law on Data takes effect |
Sources and References
| Source | Type |
|---|---|
| Law No. 24/2018/QH14 on Cybersecurity - Official English Text | Primary Source |
| DLA Piper - Data Protection Laws in Vietnam | Legal Analysis |
| Lexology - Vietnam Data Localization Requirements | Legal Analysis |
| Freshfields - Data Localization in Vietnam | Legal Analysis |
| Ministry of Public Security Vietnam | Government Source |
Requirements for a company
What an organisation has to do under Vietnam - Cybersecurity Regulation (24/2018/QH14), at a glance. Not legal advice.
Related Regulations
© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash