Law on Cybersecurity (Vietnam)

Asia-PacificGeneral Cybersecurity2018
ByDecipherU Editorial

Vietnam's Cybersecurity Law (No. 24/2018/QH14) took effect on January 1, 2019. It requires domestic and foreign service providers operating in Vietnam to store data locally, establish local offices, and cooperate with authorities on cybersecurity investigations. The law applies to operators of national information systems, critical infrastructure, and platforms with significant Vietnamese user bases.

Quick Reference

EnactedJune 12, 2018; effective January 1, 2019
Last AmendedDecree 13/2023/ND-CP (personal data protection, effective July 2023)
Enforcement BodyMinistry of Public Security, Ministry of Information and Communications
PenaltiesAdministrative fines, service suspension, and criminal penalties including imprisonment for serious violations
Applicable ToDomestic and foreign enterprises providing services on telecommunications networks, the internet, or value-added services in cyberspace in Vietnam

Key Requirements

Article 26 (Data Localization)

Domestic and foreign service providers must store data of Vietnamese users in Vietnam when requested by the Ministry of Public Security; foreign providers must establish a branch or representative office in Vietnam

Article 10 (Critical Information Systems)

Operators of critical information infrastructure must classify systems, implement appropriate security measures, and comply with security standards issued by the Ministry of Public Security

Decree 13/2023 (Personal Data Protection)

Data controllers must obtain consent for processing personal data, conduct impact assessments for sensitive data, and transfer data internationally only when adequate safeguards are in place

How Does Vietnam Cybersecurity Law Affect Cybersecurity Careers?

Vietnam's tech sector is growing rapidly, with many multinational companies establishing operations there. Security engineers and GRC analysts at these organizations must understand data localization requirements and work with local security authorities. The data localization mandate affects cloud architecture decisions and requires security professionals who understand both local regulations and global data flow management.

Cybersecurity Roles That Work With Vietnam Cybersecurity Law

Related Cybersecurity Certifications

Related Cybersecurity Laws

Frequently Asked Questions

Vietnam's Cybersecurity Law (No. 24/2018/QH14) took effect on January 1, 2019. It requires domestic and foreign service providers operating in Vietnam to store data locally, establish local offices, and cooperate with authorities on cybersecurity investigations. The law applies to operators of national information systems, critical infrastructure, and platforms with significant Vietnamese user bases.

Vietnam's tech sector is growing rapidly, with many multinational companies establishing operations there. Security engineers and GRC analysts at these organizations must understand data localization requirements and work with local security authorities. The data localization mandate affects cloud architecture decisions and requires security professionals who understand both local regulations and global data flow management.

Administrative fines, service suspension, and criminal penalties including imprisonment for serious violations

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?