If the Law on Personal Data Protection (Law on PDP) is the "original law" on privacy, the Draft Law on Cyber Security (Amendment - Law on Cyber Security) raises the issue of data protection in the wider cyberspace, while the Draft Law on Artificial Intelligence tackles the new problem of how artificial intelligence systems - which live on data - still respect the rights of children people, privacy, and avoidance of deviance.

Source: The Saigon Times
All three laws form a "triangle" that regulates and complements each other but also has the potential to overlap if not designed and implemented harmoniously.
The Law on PDP establishes a specialized legal framework for personal data. Law on dentification of basic personal data sensitive personal data; establishing the core rights of data subjects such as the right to know, consent, access, rectification, deletion, restriction of processing, objection, complaints, claims, etc.; at the same time, it stipulates the obligations of the controller and the data processor throughout the entire data lifecycle - from collection, storage, use to transfer and deletion. The law also includes in Vietnamese law the mechanism of "assessing the impact of data processing" and "assessing the impact of data transfer abroad" according to international standards.
The draft Law on Cyber Security (amended) expands the scope to the entire cyberspace. The draft determines that it will regulate "cyber security, cyber security protection; rights, obligations and responsibilities of relevant agencies, organizations and individuals". Cyber security is understood as the stability and safety of cyberspace, ensuring that information, data and activities on the network do not harm national security, social order and safety, and the legitimate rights and interests of agencies, organizations and individuals. In other words, data protection (including personal data) is part of the Cyber Security Law, not separate.
The draft Law on Artificial Intelligence (AI Law) is a newer legislative "wave", aiming at the management of AI systems in all fields. The draft affirms the first principle: "Human-centered: Artificial intelligence systems must serve and support people, respect human dignity, freedom, privacy...". This is the first time that privacy has been directly stated as a foundational principle in a specialized new technology law. The AI law also builds a risk-based management mechanism, classifies AI systems, and sets the obligation to assess impact, transparency, labeling, and accountability for systems with high risks to human rights and privacy.
The three layers of privacy barriers
Although coming from different "angles" from data, cybersecurity, to AI, all three laws share a common value axis of respecting and protecting personal privacy.
With the Law on PDP, privacy is concretized into the right to control one's own data. No one may collect and process data without a lawful basis; The data subject has the right to withdraw consent, request erasure or restrict processing when the purpose has been achieved or is no longer suitable.
Meanwhile, the Draft AI Law puts privacy at the heart of the risk assessment mechanism. Before putting into operation a high-risk AI system or having a significant impact on human rights, state agencies must prepare an impact assessment report; In which, it is necessary to analyze "the level of risk of the system", "potential impacts on human rights, privacy, social justice", "risk of disclosure of personal information, bias, discrimination" and preventive and remedial measures. Thus, privacy becomes a mandatory evaluation criterion in AI design and deployment.
Finally, the Draft Law on Cyber Security protects privacy from a "defensive angle": listing prohibited acts in cyberspace, including "illegally collecting, using, distributing, exchanging, transferring, and trading information and personal data of others". Acts of attacking the system, appropriating data stored and transmitted through telecommunications networks, the Internet, and computer networks are also prohibited and the system manager is required to apply preventive and preventive technical measures
Looking from the top, it can be seen that personal privacy is "fenced" by three rings: the core ring is the rights of data subjects from the Law on PDP, the middle ring is the safe and responsible design mechanism of the AI system from the AI Law, and the outer ring is the protection layer of network infrastructure against attack and abuse of the Law on Security.

Source: The Saigon Times
What is the solution when all 3 new regulations have an impact on businesses?
The intersection of the three laws creates a complex compliance picture but also opens up opportunities to restructure data governance and technology in the enterprise.
Firstly, in terms of organization, it is almost impossible for businesses to continue to operate in a "one part per piece" style. It is necessary to form an integrated and effective governance structure. It can be a data and technology governance board including legal, IT, business, cybersecurity, marketing to jointly appraise new projects using data and AI. In addition, it is necessary for businesses to appoint personnel in charge of personal data protection to closely coordinate with the cybersecurity department. Because in addition to supporting departments, this personnel will be the focal point responsible for state agencies in the following issues: data impact assessment reports, AI impact assessment reports, and coordination in handling cyber security incidents.
Second, in terms of processes, businesses should standardize a common "compliance chain" for all data/AI processing projects: (i). Data mapping[1] and data classification: know what types of personal data you have, where, whether it belongs to a sensitive group or not, whether it is transferred abroad or used for AI or not. (ii) Risk screening: if the project is only at a low risk level, such as internal data analysis, which does not strongly affect personal interests, a simplified process can be applied; if the project has automated decision-making AI, related to finance, healthcare, etc affair... then the consolidated impact assessment process must be activated according to the guidance of the Law on PDP and the Law on AI. (iii). Check cybersecurity requirements: enterprises need to determine what level their system is using, whether it is in the list of systems important to national security; how to certify, test, and drill cybersecurity; whether user data must be stored in Vietnam. From there, offer effective solutions to respond to new compliance requirements.
Third, in terms of technology, instead of considering legal requirements as a burden, businesses can take advantage of them to upgrade their competitiveness. Businesses consider investing in a data management platform, allowing personal data labeling, access control, and automatic anonymization of data used for AI training. Deploying[2] a centralized logging and log analysis solution, both meeting the Law on Cyber Security, and serving AI accountability and data breach investigation. In addition, building transparent and standard modules for reuse for many products, avoiding "manual tailoring" each time is also a solution worth considering.
From the perspective of privacy, it can be said that the Law on PDP, the Draft Law on Cyber Security and the Draft Law on AI are not three separate "islands", but are gradually forming a multi-layered legal ecosystem. However, these new legal frameworks bring many challenges for businesses. The biggest challenge in the coming years will be to turn this intersection into a harmonious whole, rather than a "matrix" of obligations that make businesses embarrassed. On the part of lawmakers, the design of an interdisciplinary reporting and inspection mechanism according to the "one-stop - multi-results" model as outlined in the Draft AI Law is a very encouraging direction.
When privacy is properly respected, when AI systems are designed responsibly, and when cyberspace is effectively protected, Vietnam not only prevents data crises, but also has the opportunity to build a safe, humane and internationally competitive digital environment.
Lawyer Nguyen Van Phuc
HM&P Law Firm
