DPO Radio

Law 24/2018/QH14 (the Vietnam Cybersecurity Law 2018) was enacted on June 12, 2018, and entered into force on January 1, 2019. Administered by the Ministry of Public Security (MPS), it established Vietnam's foundational cybersecurity regulatory framework, covering cybersecurity obligations for organizations operating information systems, online platforms, and digital infrastructure within Vietnam. It was the first comprehensive cybersecurity statute in Vietnam and created the primary obligations for incident response and notification, authority cooperation, data localization, and in-scope determination that have shaped cybersecurity compliance practice in the country.
Law 24 remained in force from January 1, 2019 until it was replaced by Law 116/2025/QH15 on July 1, 2026. While no longer the governing cybersecurity framework, organizations that operated during the Law 24 period remain responsible for maintaining historical compliance records, evidence, and documentation created under its requirements. These records continue to support inspections, audits, and transition assessments under the current framework.
The practical significance of Law 24 today extends beyond its historical role as Vietnam's foundational cybersecurity framework. Organizations subject to Law 24 built compliance programs, completed in-scope determinations, established incident response procedures, implemented data localization measures, and created authority cooperation protocols under its requirements. Understanding those requirements remains necessary to assess the completeness of historical compliance programs, correctly scope evidence retention for the Law 24 period, and understand the transition from Law 24 to Law 116/2025/QH15.

The Vietnam Cybersecurity Law 2025 (Law 116/2025/QH15) replaced Law 24/2018 on July 1, 2026, becoming Vietnam's current cybersecurity framework. For organizations managing current cybersecurity obligations, see the Vietnam Cybersecurity Law 2025 (Law 116/2025/QH15) compliance page.
Law 24 is the predecessor framework on which Law 116 builds. Organizations that operated under Law 24 retain historical compliance records, evidence, and governance documentation that remain relevant for inspections, audits, and transition assessments. Understanding the relationship between the two laws helps organizations distinguish legacy obligations from current requirements while maintaining an accurate compliance history.
Organizations should retain historical compliance evidence and clearly attribute it to the framework that applied at the time. Incident records, authority cooperation logs, in-scope determinations, data localization documentation, and other compliance evidence created under Law 24 should remain identifiable as legacy records alongside current compliance activities under Law 116. Maintaining this distinction supports inspections, audits, evidence continuity, and an accurate historical compliance record.
| Obligation | Requirement | Implementing Reference |
|---|---|---|
| In-scope determination | Organizations providing domestic online services, storing or processing data affecting national security, social order, or economic rights must determine their in-scope status | Law 24, Article 26; Decree 13/2022 |
| Data localization | In-scope organizations must store "important data" domestically; foreign organizations must maintain a local representative or office | Law 24, Article 26 |
| Cybersecurity incident notification | Organizations must notify MPS of cybersecurity incidents that affect information systems, with notification to authority through defined channels | Law 24, Article 18 |
| Authority cooperation | Organizations must cooperate with MPS cybersecurity investigations, provide system access when required, and respond to information requests | Law 24, Articles 23, 24 |
| Cybersecurity condition compliance | Organizations operating important information systems must maintain prescribed cybersecurity conditions, conduct periodic security reviews, and submit to MPS audits | Law 24, Articles 22, 23 |
| Content removal | Platforms must respond to MPS requests to remove unlawful content within prescribed windows | Law 24, Article 16 |
| User data provision | In-scope organizations must provide user data to MPS upon request in accordance with legal requirements | Law 24, Article 26 |
In-scope determination was one of the foundational compliance obligations under Law 24. Decree 13/2022/ND-CP specified the following criteria.
| Criterion | Threshold | Implication |
|---|---|---|
| Service type | Domestic online services (telecommunications, internet, payment, e-commerce, social networking, search, email, and others) | All major digital service categories are potentially in-scope |
| User count or data volume | MOrganizations with significant user bases or data volumes affecting national interests | Threshold assessment required; no single published number – assessment based on service and data type |
| Data type | Data affecting national security, social order, public health, or economic rights | Data classification assessment required to identify qualifying data |
| Regulatory designation | Critical information infrastructure operators as designated by sector regulators | Check applicable sector regulatory designation |
| Obligation | Timeline | Reference |
|---|---|---|
| Cybersecurity incident notification to MPS | Within prescribed window based on incident severity | Law 24, Article 18 |
| Response to MPS information requests | Within the window specified in the MPS request | Law 24, Article 23 |
| Content removal upon MPS order | Within 24 hours of MPS notification | Law 24, Article 16 |
| Cybersecurity condition compliance | Ongoing; periodic review required | Decree 13/2022 |
Law 24/2018 remains operationally relevant for organizations maintaining historical cybersecurity compliance records and evidence.
Law 24 governed Vietnam's cybersecurity framework from January 1, 2019 until June 30, 2026. Organizations that operated during this period created compliance records under its requirements, including incident notifications, authority cooperation records, in-scope determinations, and data localization documentation. These records remain part of an organization's historical compliance evidence and should continue to be retained and accessible.
Historical compliance evidence created under Law 24 reflects the legal requirements that applied at the time. Regulators conducting inspections or audits may review activities undertaken during the Law 24 period, making it important that incident records, authority cooperation logs, governance decisions, and supporting documentation remain complete, accessible, and clearly attributed to the correct legal framework. Evidence created under Law 24 should remain distinct from records produced under Law 116.
Law 24 provides the historical baseline from which organizations transitioned to Law 116/2025/QH15. Understanding what was implemented under Law 24, including in-scope determinations, data localization measures, incident response procedures, and governance controls, helps demonstrate how cybersecurity compliance evolved over time. Maintaining that baseline supports structured governance, evidence continuity, and an accurate historical compliance record.

ComplianceOne supports organizations managing Law 24 compliance records through its cybersecurity incident operations, authority cooperation, and program governance capabilities, with evidence continuity features that preserve historical compliance records alongside the current Law 116 framework.
The Incident Response module manages cybersecurity incident case records created under Law 24's notification requirements. Each case captures the incident discovery timestamp, assessment timeline, notification to MPS, and any authority follow-up, preserving the evidence chain of custody that demonstrates compliance with the notification obligation. Incident cases can be attributed to the applicable legal framework based on the incident date, ensuring that historical Law 24 records remain clearly distinguished from records created under Law 116.
The Monitoring Programs module manages authority cooperation records under Law 24, including MPS information requests, system access requests, and user data provision requests, through a structured workflow with verification, legal review, approval, and disclosure logging. Each authority interaction is captured in the centralized disclosure register with the legal basis, scope, approving authority, and response details. This register preserves historical evidence of Law 24 authority cooperation and supports future inspections and audits.
For in-scope determination and data localization documentation, the Program Governance module records the in-scope assessment, the criteria applied under Decree 13/2022, the determination outcome, and the data localization measures implemented. These records provide the historical evidence of an organization's Law 24 compliance program and remain part of its long-term compliance archive.
Manages cybersecurity incident notification workflows under Law 24's notification requirements with timestamp-based compliance evidence.
Explore IncidentsHandles MPS authority cooperation workflows (information requests, system access, user data provision) with centralized disclosure logging.
Explore Monitoring ProgramsDocuments in-scope determination, data localization compliance, and cybersecurity condition compliance reviews under Decree 13/2022.
Explore Program GovernanceMaintains tamper-evident historical records for the full Law 24 compliance period, supporting post-transition inspection readiness.
Explore Audit TrailOrganizations maintaining Law 24/2018 compliance records should confirm:
Ready to see how ComplianceOne manages Law 24/2018 compliance records, preserves historical evidence, and maintains continuity alongside Law 116? Request a demo tailored to your organization's cybersecurity compliance needs.

Law 24/2018/QH14 remained the governing cybersecurity framework until July 1, 2026, when it was replaced by Law 116/2025/QH15 (the Vietnam Cybersecurity Law 2025). Organizations that operated in Vietnam during the Law 24 period should retain compliance records and evidence created under that framework as part of their historical compliance record.
The most significant consideration is maintaining a complete historical compliance record. Organizations should retain Law 24 compliance records, evidence, and governance documentation while clearly distinguishing them from records created under Law 116. ComplianceOne's Program Governance module supports framework-specific record management and evidence continuity.
In-scope determination under Decree 13/2022 requires assessment against four primary criteria: service type (whether the organization provides one of the designated domestic online service categories), user count or data volume (whether the scale of operations affects national interests), data type (whether the data processed affects national security, social order, or economic rights), and regulatory designation (whether the organization has been designated as critical information infrastructure). The assessment must be documented with the criteria applied, data gathered, and determination reached.
Law 24 compliance records must be retained per applicable retention schedules even after Law 116 takes effect. Regulators may examine historical compliance conduct under the framework applicable at the time, meaning Law 24 records remain relevant for any inspection covering periods before July 1, 2026. These records should be maintained in accessible form and clearly attributed to the Law 24 compliance period.

Test Law 24/2018 incident operations, authority cooperation, and in-scope determination workflows with your team – including transition readiness assessment.

Talk to our team about Law 24/2018 compliance management, transition planning to Law 116, and dual-track cybersecurity compliance for your organization.