Vietnam Law on Cybersecurity (No. 116/2025/QH15)
Data security, localisation and logs (Articles 25, 26; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)

Vietnam Law on Cybersecurity (No. 116/2025/QH15) VNCS-25-LOC: Store Vietnamese users' data in Vietnam; foreign providers in listed sectors must store it and open a branch or office once the Minister so decides

Enterprises that collect or process personal information, relationship data or data created by users in Vietnam must protect it and store it in Vietnam. Decree 333 lists the data (users' personal information; account names, usage time, card information, email, latest login and logout IP addresses, registered phone numbers). Domestic enterprises must store it in Vietnam; foreign enterprises in telecom, cloud storage and sharing, domain services, e-commerce, online payment, ride-hailing, social media, online games, online applications and messaging or calling services must do so and open a branch or representative office when their service has been used for violations and, after 3 written requests over up to 6 months, they have not remedied or complied, within 12 months of the Minister of Public Security's decision. Storage runs for at least 24 months, in a form the enterprise chooses that allows timely retrieval.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Data security, localisation and logs (Articles 25, 26; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.