Corporate responsibilities under Vietnam’s cybersecurity law 2025: security is no longer optional
Vietnam’s Personal Data Protection Law No. 91/2025/QH15 took effect on January 1, 2026, while Cybersecurity Law No. 116/2025/QH15 became effective on July 1, 2026. The new rules expand corporate responsibilities for data protection, risk governance, incident response and cooperation with competent authorities. These are regulatory requirements and are not associated with any specific CVE.
Data protection and cybersecurity are increasingly moving beyond purely technical concerns to become part of broader corporate governance responsibilities. The National Cybersecurity Association (NCA) has emphasized that businesses are not only responsible for delivering products, platforms and services, but also for how systems and data under their control are protected.
This shift comes as data-related risks in Vietnam continue to become more visible. In the first six months of 2025 alone, authorities detected and handled 56 cases involving the illegal trading of personal data, with more than 110 million records unlawfully collected and exchanged.

How do the two new laws change corporate responsibilities?
The most significant change is not that businesses are required to purchase a particular security product. Rather, companies increasingly need to be able to demonstrate that they have organized appropriate measures to protect systems and data.
Vietnam’s Cybersecurity Law 2025 consolidates a number of provisions previously governed by the 2018 Cybersecurity Law and the 2015 Law on Cyberinformation Security, while further clarifying the responsibilities of companies providing services in cyberspace. The law took effect on July 1, 2026.
Meanwhile, Personal Data Protection Law No. 91/2025/QH15, effective January 1, 2026, places specific responsibilities on parties involved in personal data processing. Data controllers must implement appropriate administrative and technical measures, safeguard the rights of data subjects, prevent unauthorized collection and cooperate with competent authorities where required.
This also means that responsibility does not automatically end when a company outsources services to a Cloud provider, SaaS vendor, marketing agency, call center or external IT provider. The roles of data controllers, data processors and third parties need to be clearly defined in contracts and operational processes.
What specific obligations should businesses pay attention to?
Not every legal requirement applies in exactly the same way to every company. A conventional business processing customer data may face different obligations from a telecommunications provider, Internet service provider or digital platform operating in Vietnam.
Requirement area | What businesses should consider |
Personal data protection | Implement appropriate administrative and technical safeguards; control processing purposes; protect data subject rights. |
Impact assessments | Personal data processing impact assessment records must be maintained and, for entities subject to the requirement, submitted within 60 days from the start of data processing. |
Data breach response | Certain violations capable of causing harm under Article 23 must be reported to the specialized authority within 72 hours of detection. |
Digital service providers | Additional obligations may apply regarding user authentication, account security, disclosure of information and handling of content following valid requests from competent authorities. |
Compliance evidence | Logs, contracts, assessment records, access policies and incident documentation should be sufficient to demonstrate the measures a company has implemented. |
Decree 356/2025/ND-CP requires personal data processing impact assessment records to remain available for inspection and, where applicable, to be submitted within 60 days from the commencement of processing. The legal framework also requires these records to be updated when specified changes occur.
For incidents, the 72-hour threshold does not mean that every technical fault must be reported. The Personal Data Protection Law requires notification when a personal data protection violation is likely to cause the types of harm identified under Article 23. This means businesses need sufficiently mature incident classification and assessment procedures from the moment suspicious activity is detected.
Decree 356 also provides certain transitional mechanisms for qualifying small businesses and startups. For five years from the effective date of the law, eligible organizations may elect not to perform certain obligations under Articles 21, 22 and Clause 2 of Article 33. However, these exemptions do not apply in several cases, including businesses directly processing sensitive personal data or processing data belonging to 100,000 or more data subjects.
What obligations should companies providing services in cyberspace pay attention to?
Businesses providing telecommunications, Internet and value-added services in cyberspace in Vietnam are subject to an additional set of obligations.
Decree 333/2026/ND-CP, effective August 19, 2026, provides further detail on user authentication and account protection, cooperation in supplying information, and the handling of unlawful content or services in response to valid requests.
In certain circumstances, the required response times are relatively short:
User information requested through a valid legal request must generally be provided within 24 hours; certain urgent cases may reduce this period to 3 hours.
Requests to restrict, remove or delete unlawful content, services or applications must generally be completed within 24 hours; urgent situations involving threats to national security may require action within 6 hours.
Businesses should be particularly careful when interpreting these requirements. These deadlines should not be treated as general obligations applicable to every company operating in Vietnam. They apply to specific categories of service providers and circumstances defined by the law and implementing regulations.
Why can responsibility no longer be assigned only to the IT department?
A strong firewall policy cannot correct a contract that permits data to be shared for an improper purpose. Likewise, security software cannot decide how long a business may retain customer information or whether a marketing employee is permitted to export customer records to a third-party platform.
Effective compliance therefore requires coordination across multiple functions:
Executive management: define risk appetite, budgets and accountability.
Legal/compliance: determine lawful processing grounds, contractual requirements and regulatory obligations.
IT/cybersecurity: implement access controls, logging, system protection and incident response.
Human resources: manage employee data and account lifecycle processes.
Marketing/sales: control data collection, consent and customer data sharing.
Procurement/vendor management: assess third parties before granting access to or transferring data.
The current cybersecurity risk landscape also shows that personal data can be exposed through multiple channels, including account compromise, excessive privileges, weak API or system configurations, unmanaged devices and third-party providers. Businesses can refer to IPSIP’s Vietnam Cybersecurity Landscape Q2 2026 report to place these regulatory requirements in the context of real-world threats.
What should businesses do now to reduce compliance risk?
The first priority should be identifying what data the organization holds and processes, rather than immediately purchasing additional security tools.
Action Checklist:
Create an inventory of personal data, sensitive personal data and the systems where the information is stored.
Determine whether the company acts as a data controller, data processor or third party for each processing activity.
Map data flows from collection and use through sharing, backup and deletion.
Review consent mechanisms, privacy notices, processing purposes and retention policies.
Review contracts with Cloud providers, SaaS vendors, agencies, call centers and other vendors that can access data.
Audit privileged accounts, MFA, Least Privilege controls and accounts belonging to former employees.
Establish sufficient logging to detect, investigate and determine the timing of security incidents.
Build an Incident Response process involving legal/compliance teams and a mechanism for assessing whether the 72-hour notification requirement applies.
Regularly assess websites, APIs, Cloud environments and other Internet-facing assets.
Provide role-based security training rather than relying only on general awareness training.
Decree 330/2026/ND-CP has been effective since August 19, 2026 and establishes specific administrative penalties for cybersecurity and personal data protection violations. Depending on the violation, measures may extend beyond monetary fines and can include temporary suspension of operations, temporary withdrawal of licenses or certificates, or mandatory deletion of data collected or processed unlawfully.
Businesses should therefore consider documentation, logs and technical evidence part of their compliance posture. Controlled information security assessments or penetration testing can help identify practical weaknesses before they develop into incidents.
What does IPSIP Vietnam’s cybersecurity perspective highlight?
Vietnam’s Cybersecurity Law 2025 and Personal Data Protection Law are moving cybersecurity beyond the boundaries of the IT department. Corporate responsibility is increasingly tied to an organization’s ability to understand its data, control access, manage third parties, detect incidents and demonstrate that appropriate safeguards have been implemented.
For businesses in Vietnam, the priority should not be indiscriminate investment in more security products. Companies should first determine the scope of their legal obligations, identify critical data and address the gaps most likely to create significant risk. Legal, governance and technical controls can then operate as one coordinated system.
References
National Cybersecurity Association (NCA) - Corporate Responsibility – A Mandatory Requirement Under the Cybersecurity Law 2025 and Personal Data Protection Law
Ministry of Public Security - Personal Data Protection Law No. 91/2025/QH15
National Database of Legal Documents - Cybersecurity Law No. 116/2025/QH15
Government of Vietnam - Decree 356/2025/ND-CP Detailing the Implementation of the Personal Data Protection Law
Government News - Requirements for Cybersecurity and Information Security Activities of Businesses Under Decree 333/2026/ND-CP
Government of Vietnam Portal - Decree 330/2026/ND-CP on Administrative Penalties in Cybersecurity and Personal Data Protection











Comments