DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX ComplianceOne | Vietnam Draft Data Security Law

Overview Image

Why the Draft Data Security Law Matters

Resolution 07/2026/UBTVQH16 added the Draft Law on Data Security to Vietnam's 2026 legislative program for consideration at the National Assembly's second session in October 2026. That schedule is a legislative-program milestone, not an effective date.

The Ministry of Public Security policy-codification dossier frames data as a national resource and links data security with digital sovereignty, national security, social order, resilience, and long-term technology autonomy. The material remains a draft and may change before adoption.

The proposal would create a broad operating challenge for organizations processing data in Vietnam or handling data connected with Vietnam. Data governance, cybersecurity, privacy, AI, vendor, platform, and infrastructure teams may need coordinated evidence covering classification, controls, storage, transfers, personnel, monitoring, and incidents.

ComplianceOne keeps this work in a clearly identified readiness track. Teams can assess exposure and build reviewable evidence while preserving the difference between proposed rules and current legal obligations.

What the Law Covers

Dimension

Coverage

National data sovereignty

Jurisdiction, national interests, data assets, foreign-platform dependencies, and domestic technology resilience.

Level 1 - Ordinary data

Open and routine operational data without sensitive elements, supported by baseline security.

Level 2 - Internal data

Data requiring organizational protection through access, governance, and risk controls.

Level 3 - Important data

Data requiring heightened protection because of its potential economic, public-interest, or social-order impact.

Level 4 - Core data

Data linked to national defense, national security, and other strategic national interests.

Aggregation

Upward reclassification where accumulated data changes the potential impact.

Lifecycle security

Collection, creation, storage, transmission, processing, sharing, provision, and destruction.

Cross-border data flows

Classification-based screening, impact and recipient assessment, storage, and proposed approval pathways.

Assurance and resilience

Monitoring, audit, risk labels, conformity readiness, personnel, training, incidents, and recovery.

The policy dossier proposes a four-level classification model that may change during the legislative process.

For proposed overseas transfers, the draft describes stricter treatment for Important and Core Data. These pathways remain draft readiness considerations and are not presented as final filing procedures.

Overview Image

How ComplianceOne Supports the Draft Data Security Law

Teams can inventory datasets, assign accountable owners, record the proposed Level 1-4 classification with rationale, and trigger reassessment when aggregation or use changes potential impact. Each information system can be linked to the highest data level it processes and the security evidence used to support that alignment.

Lifecycle reviews connect collection, storage, transmission, sharing, and destruction controls with policies, access decisions, responsible personnel, training, monitoring, incidents, and recovery. Department contributors can provide evidence while central reviewers retain decision and approval history.

Cross-border screening can branch according to classification, destination, recipient conditions, personal-data overlap, and proposed authority pathways. Security impact and recipient assessments remain connected to approval readiness and post-transfer monitoring.

AI-related evidence can be linked where data security obligations intersect with the separate AI Law, without duplicating AI governance workflows. The same approach preserves connections with the Data Law, personal data protection law, Cybersecurity Law, the electronic identification and authentication draft, Electronic Transactions, telecommunications, and e-commerce rules.

Related Modules

Data DiscoveryData Discovery

Identifies datasets, sources, systems, owners, and material changes.

Explore Data Discovery

Data ClassificationData Classification

Records Level 1-4 rationale, aggregation review, and approval history.

Explore Data Classification

Data MappingData Mapping

Connects lifecycle stages, storage, recipients, systems, and cross-border flows.

Explore Data Mapping

Monitoring ProgramsMonitoring Programs

Coordinates recurring review, control testing, training, and assurance evidence.

Explore Monitoring Programs

Incident OperationsIncident Operations

Preserves detection, containment, recovery, decisions, and closure evidence.

Explore Incident Operations

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconDataset inventories lack consistent ownership and classification rationale.
IconEvery dataset has an owner, proposed classification, rationale, and review history.
IconAggregated data keeps an outdated lower classification.
IconAggregation and material changes can trigger upward reassessment.
IconSystem security evidence is disconnected from the highest data level processed.
IconSystem controls remain linked to the highest data level and supporting evidence.
IconCross-border reviews miss classification, recipient, or personal-data context.
IconTransfer readiness joins classification, impact, recipient, approval, and monitoring records.
IconPolicy, personnel, training, monitoring, AI, and incident evidence remains fragmented.
IconDraft status, legislative milestones, sources, and later changes remain traceable.

Built for Compliance Operations

Build For Image

ComplianceOne records the legislative-program basis and links readiness work to the Ministry of Public Security policy-codification dossier.

Build For Image

The readiness set uses organization-created working records. It does not present government forms, final fines, final procedures, a final effective date, or the October 2026 session as a compliance deadline.

Build For Image

Human review remains central to classification, legal interpretation, transfer decisions, evidence approval, and any future authority interaction.

Background Image

See Data Security Compliance in Action

See how ComplianceOne structures classification, lifecycle, transfer, monitoring, and incident evidence without overstating the draft's legal status.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

No. The source is a 2026 policy-codification dossier in the legislative program. October 2026 is a scheduled National Assembly milestone, not an effective date.

The proposal currently describes Ordinary, Internal, Important, and Core Data, with progressively stronger security and data-flow controls based on potential impact.

The draft proposes reassessing lower-level data when accumulation or aggregation increases potential harm to national security, social order, public interests, or individual rights.

It proposes classification-based controls, including stronger screening and approval pathways for Important and Core Data. ComplianceOne treats these as readiness considerations until final law and procedures are verified.

It connects dataset inventory, classification, lifecycle controls, system alignment, transfer assessments, personnel, training, monitoring, AI evidence, incidents, and source-traceable review history.

Next Steps

Icon Image

Start a Compliance Pilot

Test data classification, lifecycle, transfer, and monitoring readiness with your team.

Icon Image

Discuss Your Compliance Needs

Map the draft proposal to your datasets, systems, providers, AI use, and existing Vietnam duties.