Updated: 23 September 2026
Which laws should an online retailer read first when it rents cloud services, uses AI for product recommendations and shares data with partners? Start with its actual activities: whose data is involved, what it is used for, which parties handle it and which systems hold it. Each question identifies a different set of obligations. Understanding how these overlap helps a business avoid completing one filing while overlooking other required work.
Which laws are in force
Data Law No. 60/2024/QH15 took effect on 1 July 2025, establishing a framework for data governance, protection, use, and data products and services. Personal Data Protection Law No. 91/2025/QH15 has applied since 1 January 2026, alongside Decree No. 356/2025/ND-CP. Their scopes overlap but are not identical: data held by a business may be personal data and also qualify as important or core data.
From 1 July 2026, Cybersecurity Law No. 116/2025/QH15 replaces the 2015 Law on Cyberinformation Security and the 2018 Cybersecurity Law under Article 44. Decrees Nos. 331 and 332/2026/ND-CP, both effective from 19 August 2026, respectively govern cybersecurity assurance by security level and the business of cybersecurity products and services. Civil cryptography is specifically governed by Decree No. 341/2026/ND-CP from 1 September 2026.
Artificial Intelligence Law No. 134/2025/QH15 took effect on 1 March 2026; Decree No. 142/2026/ND-CP took effect on 1 May 2026. Data centre and cloud computing services must also be assessed under the Telecommunications Law and its implementing rules, including the 2026 provisions on delegation of authority and procedural simplification.
Start with activities rather than registered business lines
Under Articles 2 and 37 of the Personal Data Protection Law, a business must establish who determines the purposes and means of processing and who processes data under contract. An organisation may be a controller for its employees' data while acting as a processor for its clients.
Next, distinguish internal use from service provision. An internal revenue analytics team is not automatically a provider of data analysis and aggregation services. Buying anti-malware software does not make a business a cybersecurity service provider. Assess the business scope against Articles 28–29 of the Cybersecurity Law, Articles 39–43 of the Data Law and the relevant sector-specific decrees.
Which authority handles each obligation
The Ministry of Public Security administers personal data protection, data and cybersecurity obligations within its statutory remit. The Government Cipher Committee receives and processes civil cryptography procedures within its authority, with separate rules for products that also have cybersecurity functions. The Ministry of Science and Technology oversees AI and telecommunications; certain data centre and cloud procedures have been delegated to provincial authorities.
Do not infer the filing destination solely from the name of the overall regulator. For example, under Article 18 of Decree No. 331, the system owner's dedicated cybersecurity unit appraises and approves Level 1 and Level 2 dossiers. Not every dossier goes to the Ministry of Public Security.
A September change to watch
Decree No. 347/2026/ND-CP, effective from 15 September 2026, changes the regulatory framework for data analysis and aggregation services and repeals certain provisions and forms under Decree No. 169/2025/ND-CP. Guidance on obtaining certificates written before that date should therefore be reviewed. Removing a procedure does not remove every condition or notification obligation.
How businesses can build an obligations register
A useful register identifies the activity, data type, role, applicable legal basis, responsible person and evidence to retain. Distinguish documents required by specific provisions from optional governance tools such as checklists and data flow diagrams. Decree No. 330/2026/ND-CP on penalties has been effective since 19 August 2026, but the underlying obligation must still be identified in the relevant law and substantive regulations.
Effective dates are part of the review. As at 23 September 2026, Decree No. 314/2026 on data exchanges is not yet effective; it applies from 25 September 2026. Decree No. 320/2026 on electronic identification and authentication takes effect on 28 September 2026. Law No. 20/2026/QH16 applies from 1 March 2027. Businesses should prepare for these dates without presenting the provisions as already effective at the article's cut-off date.
Which regulatory layers apply to a data activity
Six layers can help organise the review: privacy and personality rights; personal data protection; data governance, classification and use; cybersecurity; sector-specific rules; and intellectual property, trade secrets and contracts. This is a way of structuring the work, not six licences that every business must obtain.
For example, health records may be sensitive personal data and subject to confidentiality requirements under Articles 10 and 69 of the Law on Medical Examination and Treatment. Article 13 of the Law on Credit Institutions imposes separate requirements for bank customer information. Consent must therefore be interpreted within its proper scope; it does not replace every sector-specific condition for disclosing information.
Follow a data flow to identify gaps
For the retailer in the opening example, review the input data and legal basis, providers' roles, overseas flows, AI system classification, information system security level and conditions for services offered to the market. Then check retention periods, how individuals' requests are handled and incident response. A software subscription agreement cannot answer all these questions.
The obligations map can use shared assessment data, with responsibility assigned for each task. The article on data protection responsibilities helps identify roles; the cloud article explains processing flows; and the data analytics licensing article distinguishes internal use from service provision. This also lets readers navigate the collection by the issue their business faces instead of reading laws in numerical order.
Frequently asked questions
Is there one licence covering all data activities? No. Licences, registrations, notifications, impact assessments and security level approvals are different regulatory tools triggered by particular activities.
Does outsourcing transfer all responsibility? No. Contracts allocate work, but statutory responsibilities remain attached to each party's role.
Legal sources
Personal Data Protection Law No. 91/2025/QH15
Decree No. 356/2025/ND-CP implementing personal data protection requirements
Cybersecurity Law No. 116/2025/QH15
Decree No. 331/2026/ND-CP on cybersecurity assurance by security level
Decree No. 332/2026/ND-CP on cybersecurity products and services businesses
Decree No. 341/2026/ND-CP on civil cryptography
Artificial Intelligence Law No. 134/2025/QH15
Decree No. 347/2026/ND-CP amending Decree No. 169
Law No. 20/2026/QH16, effective from 1 March 2027
Law on Medical Examination and Treatment No. 15/2023/QH15 — Articles 10 and 69
Law on Credit Institutions No. 32/2024/QH15 — Articles 13 and 14
Decree No. 330/2026/ND-CP on penalties for cybersecurity and personal data protection violations
Decree No. 314/2026/ND-CP on data exchanges — effective from 25 September 2026
Sources checked through 23 September 2026.
Related articles
Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026
Article 07 Vietnam Data Law and the Classification of Core and Important Data
Article 10 Vietnam Cybersecurity Law Changes for Businesses in 2026
Article 16 Vietnam AI Law and System Risk Classification in 2026
Article 18 Vietnam Data Centre Services Registration and Licensing
Article 21 Vietnam Personal Data Protection Templates and How to Use Them
