Draft Decree guiding the Law on Cybersecurity: What do cross-border business enterprises need to prepare?

Resources
    Draft Decree guiding the Law on Cybersecurity: What do cross-border business enterprises need to prepare?
    Posted on: 25/05/2026

    The Draft Decree detailing a number of articles and measures to implement the Law on Cyber Security 2025 (the "Draft Decree")[1] is attracting great attention from the business community, especially enterprises providing cross-border services in Vietnam. According to the content of the Draft, the drafting agency is aiming to establish a stricter and more synchronous cyber security management mechanism, including issues such as: cyber security protection measures, ensuring network information security, IP address identification management and data storage mechanism in Vietnam.

     

    For many cross-border businesses, this can be a significant change to the global operating model, data governance structure, user control process, and technology infrastructure investment strategy in Vietnam.

     

    Notably, the Draft not only affects large technology enterprises or international social networking platforms, but also directly affects many foreign businesses that are providing services to users in Vietnam through the Internet. In the context that the Law on Cybersecurity 2025 will officially take effect from July 1, 2026, early identification of compliance obligations and the development of appropriate adaptation roadmaps are especially important for businesses.

    From "post-inspection management" to "proactive control" in cyberspace

    If in the past, Vietnam's cyber security regulations mainly focused on handling violations or requiring coordination when incidents occurred, this Draft Decree shows the trend of shifting to a "proactive control" mechanism for service provision activities in cyberspace.

    This is evident in the fact that the Draft simultaneously sets many new obligations for enterprises, including: storing data in Vietnam, authenticating user identities, keeping system logs, coordinating IP address identification, providing information to competent authorities in a very short time and implementing a mechanism for handling infringing content according to requirements of management agencies[2].

    In fact, these requirements are not merely additional administrative procedures. For many cross-border businesses, this can be a significant change to the global operating model, data governance structure, user control process, and technology infrastructure investment strategy in Vietnam.

    Data storage obligations in Vietnam: the biggest pressure on cross-border businesses

    One of the most notable contents of the Draft Decree is the regulation on data storage and commercial presence in Vietnam for foreign enterprises. According to Article 24 of the Draft, foreign enterprises operate in many fields such as: telecommunications services, e-commerce, social networks, online payments, online video games, online applications, data storage and sharing in cyberspace, etc. may have to perform the obligation to store some types of data in Vietnam.

    Groups of data that must be stored include:

    • Personal data of users in Vietnam;
    • Data generated by users in Vietnam; and
    • Data on the relationship of service users in Vietnam.

    In essence, this regulation can be seen as a form of data localization – a [3] legal trend that is emerging in many countries to strengthen the ability to control data in the country. However, for cross-border businesses, the actual implementation may arise many significant difficulties.

    First, businesses may have to adjust their global data system architecture to separate Vietnamese user data from existing regional data clusters or centralized storage systems.

    Secondly, investing in or renting storage infrastructure in Vietnam will significantly increase operating costs, especially for businesses that do not have a commercial presence in Vietnam.

    Third, businesses may have to review their cross-border data sharing mechanisms to ensure that they comply with Vietnamese laws and data protection laws of other countries such as the European GDPR or international data transfer regulations in the country where the business is located.

    Notably, the Draft also stipulates that foreign enterprises may have to set up branches or representative offices in Vietnam if their services are used to commit violations of the law on cyber security and the enterprise fails to take remedial measures at the request of the competent authority after repeated requests for coordination.

    This regulation shows that the regulator is looking to strengthen the ability to enforce the law for cross-border platforms that were previously difficult to access or enforce legal obligations in Vietnam.

    User authentication obligations: major changes to the operating model of digital platforms

    Another noteworthy point is the requirement to authenticate user information according to Vietnamese law. According to the Draft, cross-border service providers are responsible for authenticating user accounts with mobile phone numbers in Vietnam or personal identification numbers in accordance with the law. This is a fundamental change for many technology businesses.

    In the past, many international platforms only required users to provide an email or phone number to receive an OTP code for account registration. However, under the new approach of the Draft, businesses may have to implement stricter identity control mechanisms and take greater responsibility for the authenticity of user information.

    This means that businesses no longer merely play the role of an "intermediary platform", but tend to become a subject directly involved in user identity authentication activities according to Vietnamese management standards.

    Technically and operationally, this is not a simple requirement. Enterprises may have to: (1) Design their own account registration process for the Vietnamese market; (2) Integrate the identity authentication system in accordance with domestic regulations; (3) Establish a mechanism for storing and managing identification data; (4) Adding technical and compliance teams to handle regulatory requirements in a short time.

    For businesses with millions of users, changing the authentication system can have a direct impact on user experience, new account sign-up rates, and also the cost of operating the platform.

    Regulatory Request Response Mechanism: Great Time and Operational Pressures

    The draft also sets out a very close coordination mechanism between businesses and competent agencies in handling infringing information in cyberspace.

    Accordingly, enterprises are responsible for: (i) Providing information for investigation within a maximum period of 24 hours; (ii) In case of emergency related to national security or human life, the time limit may be only 03 hours; (iii) Remove the content or restrict access to the infringing content for a maximum period of 24 hours; (iv) In case of national security-related emergencies, the time limit may be shortened to 06 hours.

    In fact, this is a huge operational pressure for cross-border businesses, especially when many businesses are operating a regional or global support system.

    To meet the above short timelines, businesses may have to:

    • Establish a legal claims handling team that operates 24/7;
    • Arrange personnel who are knowledgeable about Vietnamese law;
    • Establish a mechanism for rapid response to requests from state agencies;
    • Build your own internal process for the Vietnamese market.

    This significantly increases compliance costs and can create a conflict between Vietnam's legal requirements and internal policies or legal obligations in other countries.

     

    In the context that the Draft Decree shows the trend of tightening cyberspace management and increasing the responsibilities of enterprises providing cross-border services, early preparation is especially necessary.

     

    IP address identification management: a new technical challenge

    In addition to user data, the Draft also sets new requirements for IP address identification management. According to Articles 27 and 28 of the Draft, telecommunications and Internet service providers must store logs of IP allocation systems for at least 12 months and must have a connection mechanism to provide IP identification information to competent authorities upon lawful written requests.

    This is a highly technical requirement and can create significant pressure on businesses. Storing adequate system logs for a long time requires businesses to invest heavily in storage infrastructure and implement security solutions to ensure that data is not modified or accessed without authorization.

    In addition, the requirement to maintain a regular technical connection mechanism with management agencies also increases the complexity of system operation, especially for enterprises with globally distributed infrastructure models.

    What should businesses prepare?

    In the context that the Draft Decree shows the trend of tightening cyberspace management and increasing the responsibilities of enterprises providing cross-border services, early preparation is especially necessary.

    Accordingly, businesses should consider performing some of the following tasks:

    First, review the data model and storage infrastructure

    Enterprises need to assess whether the current system meets the data storage requirements in Vietnam; at the same time, determine which data groups are likely to fall within the scope of storage according to the Draft.

    Second, re-evaluate the user authentication mechanism

    Businesses providing online platforms should review the account registration process, identity mechanism, and user management policies to prepare for the possibility of having to authenticate according to local standards.

    Third, develop a quick response mechanism to the requirements of management agencies

    Enterprises should establish a legal and technical focal point in Vietnam or the region to handle requests for information, remove content or coordinate investigations within a short period of time as prescribed.

    Fourth, assessment of cross-border legal conflicts

    For multinational corporations, it is necessary to review the risk of conflict between the Draft Decree and data protection or privacy regulations in other countries to develop an appropriate compliance plan.

    Finally, businesses should closely monitor the process of completing the Draft

    Currently, the Draft is still in the process of being finalized and can continue to be edited before its official promulgation, which is expected to take effect from July 1, 2026. Therefore, businesses need to closely monitor changes to proactively update appropriate compliance plans.

    The draft Decree guiding the Law on Cyber Security 2025 shows the trend of strengthening Vietnam's cyberspace management in a more proactive, comprehensive and enforceable direction. For cross-border businesses, new regulations not only create additional compliance obligations, but can also directly impact technology architecture, operating models, data governance strategies, and long-term investment costs. In this context, proactively identifying legal risks early, assessing operational impacts and developing appropriate compliance roadmaps will be important factors to help businesses maintain stable operations and limit legal risks in the Vietnamese market in the coming time.

    Nguyen Ngoc Ky Duyen – Bui Hoang Nhat Minh

    HM&P Law Firm


    [1] The Law on Security, last accessed on 24/05/2026, details a number of articles and measures to implement the Law on Security.

    [2] Article 24 of the Draft.