分享好友 越南资讯首页 越南资讯分类 切换频道

Vietnam's Draft Decree for Data Law Implementation

2025-04-25 11:1420Chú Tàivietnam-briefing

In this series about data regulation in Vietnam, we explore the key aspects of the proposed regulations and their potential impact on data-related businesses in the country. This article specifically focuses on the draft Implementation Decree, which aims to clarify the general provisions outlined in the Data Law.


Following the introduction of Law No. 60/2024/QH15 on Data (“Data Law”) in November 2024, Vietnam’s government has yet to fill the gap of detailed regulations needed to guide the actual implementation of this milestone law. However, a series of new regulatory instruments will soon address the void, whose drafts were released in January 2025. These documents include:

Vietnam is currently preparing four legal documents to facilitate the enforcement of its new Data Law, set to take effect on July 1, 2025. In this series on Vietnam’s data regulation, we examine the key aspects of these proposed regulations and their potential impact on data-related businesses in Vietnam.

Essential and core data identifications

The draft Implementation Decree specifies criteria for recognizing essential and core data. Generally, essential data is information potentially influencing national defense, security, foreign relations, macroeconomic stability, social order, public health, and community safety. Meanwhile, core data pertains to information that has a direct impact on these sectors. 

Data Classification Criteria

Category

Criteria

Impacted area

Essential data

Impact on national security, sovereignty, and territorial integrity

Defense, political stability, economic security, social order, public health, and safety (excluding state secrets).

Impact on foreign relations and international cooperation

Strategic partnerships, overseas projects, energy security, maritime routes.

Impact on economic development

Macroeconomic stability, critical infrastructure, and key industries.

Impact on individuals and organizations

Life, health, property, legal rights, and reputational risks.

Core data

Party and State policies

Domestic/foreign policies, leadership activities, ethnic/religious strategies.

National defense and security

Military operations, critical infrastructure, weapons systems, cryptography.

Strategic economic and industrial data

Monetary policy, rare resources, and national reserves.

Scientific and technological advancements

Defense-related patents, nuclear/atomic research, and rare pharmaceuticals.

Population and legal oversight

Census data, anti-corruption, and legal investigations.

International agreements and treaties

Data exchanged with foreign entities under binding treaties.

Obligations for data transfer

Cross-border data transfer

According to the draft decree, for transferring essential and core data abroad, data administrators must thoroughly assess related risks to build mandatory impact assessment reports, including:

Data administrators are required to prepare and submit the necessary documents, along with a notification, to the relevant data regulators at least five days prior to transferring data, which includes:

Nonetheless, the approval for transferring core data is stricter compared to that for essential data, as detailed below:

Data administrators are also required to perform an annual self-assessment of risks related to the transfer and processing of essential data, as well as a bi-annual assessment for core data. These assessments must be reported to the Ministry of Public Security.

Additionally, regardless of the data category being transferred internationally, the data transferor must safeguard the legitimate rights and interests of the data subject, along with national defense, security, and public interests. An agreement must also be established with the recipient, which includes the clearly defined mandatory content.

Data transfer in mergers, restructurings, or bankruptcies

The draft Implementation Decree states that if a data administrator must transfer data during cases of a merger, reorganization, or bankruptcy, data administrators must inform affected users through a phone call, text message, email, or notice, and submit a transfer plan.

Data protection measures

The draft decree establishes principles for managing data access and extraction, along with specific requirements for processing core data and essential data.

Data validation

Pursuant to the draft decree, the responsibility for data validation lies with both the database owner and the data subject. However, the database owner has the ultimate responsibility for ensuring the quality of the data in their database. The database owner, the database operator, or a digital verification service provider has the right to perform data validation. Verified data has the same legal value as the original data for a certain period, as the competent authority prescribes.

Data disclosure restrictions

Disclosure-prohibited data

The draft decree prescribes the following data types, which must not be publicly disclosed:

Conditionally disclosable data

The following information may be disclosed under certain conditions:

Data security

To guarantee safety, the Draft Decree requires implementing one or more encryption measures for data management, which include:

Simultaneously, decryption protocols must require identity verification of the individual decrypting the data and authorized access to encrypted information. All encryption and decryption activities must be documented for validity, transparency, and accountability.

It is worth noting that many of the measures being imposed are inspired by best practices in personal data protection (for example, record of processing activities, access controls, training of employees, proper deletion and destruction procedures, etc.). Although one would understand why such measures would be relevant in the case of core and important data, the requirements would be very burdensome for “ordinary” data processing. The scope of application of the Data Law (and its future guiding decrees) will cover any organization participating in or related to digital data activities. As digital data is simply data in digital form, the application scope is very broad, and the obligations far-reaching.

Procedures for data provision to state agencies

The Draft Decree outlines the procedures for state authorities to obtain data from organizations and individuals. State agencies must issue written requests for data access. Verbal requests are allowed only in emergencies and must be followed by confirmation.

Each data request should detail the type of data, the required detail level, the amount of data, the frequency of access, and the method of provision. These requests must honor the legitimate purposes of the data administrator and the data owner, while ensuring the protection of business secrets and personal privacy.

A data request can be withdrawn under specific conditions, such as:

The draft decree allows data owners, legal representatives, or individuals legally managing and utilizing the data to request changes or cancel the data request from the respective State authority, as long as such requests are made before the established data provision deadline.

Takeaways for businesses

The draft Implementation Decree is designed to enhance the forthcoming Data Law by establishing clear criteria for classifying data and implementing strict protocols for cross-border data transfers, thereby protecting national security and public interests.

As companies gear up for these changes, it becomes imperative to comply with the new requirements to ensure data integrity and remain aligned with shifting legal standards. To adjust successfully to these legal modifications, businesses should:

点赞 0
举报
收藏 0
评论 0
分享 0
更多相关评论
暂时没有评论,来说点什么吧