DPO Radio

Resolution 07/2026/UBTVQH16 added the Draft Law on Data Security to Vietnam's 2026 legislative program for consideration at the National Assembly's second session in October 2026. That schedule is a legislative-program milestone, not an effective date.
The Ministry of Public Security policy-codification dossier frames data as a national resource and links data security with digital sovereignty, national security, social order, resilience, and long-term technology autonomy. The material remains a draft and may change before adoption.
The proposal would create a broad operating challenge for organizations processing data in Vietnam or handling data connected with Vietnam. Data governance, cybersecurity, privacy, AI, vendor, platform, and infrastructure teams may need coordinated evidence covering classification, controls, storage, transfers, personnel, monitoring, and incidents.
ComplianceOne keeps this work in a clearly identified readiness track. Teams can assess exposure and build reviewable evidence while preserving the difference between proposed rules and current legal obligations.
Jurisdiction, national interests, data assets, foreign-platform dependencies, and domestic technology resilience.
Open and routine operational data without sensitive elements, supported by baseline security.
Data requiring organizational protection through access, governance, and risk controls.
Data requiring heightened protection because of its potential economic, public-interest, or social-order impact.
Data linked to national defense, national security, and other strategic national interests.
Upward reclassification where accumulated data changes the potential impact.
Classification-based screening, impact and recipient assessment, storage, and proposed approval pathways.
Monitoring, audit, risk labels, conformity readiness, personnel, training, incidents, and recovery.
The policy dossier proposes a four-level classification model that may change during the legislative process.
For proposed overseas transfers, the draft describes stricter treatment for Important and Core Data. These pathways remain draft readiness considerations and are not presented as final filing procedures.

Teams can inventory datasets, assign accountable owners, record the proposed Level 1-4 classification with rationale, and trigger reassessment when aggregation or use changes potential impact. Each information system can be linked to the highest data level it processes and the security evidence used to support that alignment.
Lifecycle reviews connect collection, storage, transmission, sharing, and destruction controls with policies, access decisions, responsible personnel, training, monitoring, incidents, and recovery. Department contributors can provide evidence while central reviewers retain decision and approval history.
Cross-border screening can branch according to classification, destination, recipient conditions, personal-data overlap, and proposed authority pathways. Security impact and recipient assessments remain connected to approval readiness and post-transfer monitoring.
AI-related evidence can be linked where data security obligations intersect with the separate AI Law, without duplicating AI governance workflows. The same approach preserves connections with the Data Law, personal data protection law, Cybersecurity Law, the electronic identification and authentication draft, Electronic Transactions, telecommunications, and e-commerce rules.
Identifies datasets, sources, systems, owners, and material changes.
Explore Data DiscoveryRecords Level 1-4 rationale, aggregation review, and approval history.
Explore Data ClassificationConnects lifecycle stages, storage, recipients, systems, and cross-border flows.
Explore Data MappingCoordinates recurring review, control testing, training, and assurance evidence.
Explore Monitoring ProgramsPreserves detection, containment, recovery, decisions, and closure evidence.
Explore Incident Operations


ComplianceOne records the legislative-program basis and links readiness work to the Ministry of Public Security policy-codification dossier.

The readiness set uses organization-created working records. It does not present government forms, final fines, final procedures, a final effective date, or the October 2026 session as a compliance deadline.

Human review remains central to classification, legal interpretation, transfer decisions, evidence approval, and any future authority interaction.
See how ComplianceOne structures classification, lifecycle, transfer, monitoring, and incident evidence without overstating the draft's legal status.

No. The source is a 2026 policy-codification dossier in the legislative program. October 2026 is a scheduled National Assembly milestone, not an effective date.
The proposal currently describes Ordinary, Internal, Important, and Core Data, with progressively stronger security and data-flow controls based on potential impact.
The draft proposes reassessing lower-level data when accumulation or aggregation increases potential harm to national security, social order, public interests, or individual rights.
It proposes classification-based controls, including stronger screening and approval pathways for Important and Core Data. ComplianceOne treats these as readiness considerations until final law and procedures are verified.
It connects dataset inventory, classification, lifecycle controls, system alignment, transfer assessments, personnel, training, monitoring, AI evidence, incidents, and source-traceable review history.

Test data classification, lifecycle, transfer, and monitoring readiness with your team.

Map the draft proposal to your datasets, systems, providers, AI use, and existing Vietnam duties.