Vietnam Law on Cybersecurity (No. 116/2025/QH15)
Data security, localisation and logs (Articles 25, 26; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)

Vietnam Law on Cybersecurity (No. 116/2025/QH15) VNCS-25-LOG: Keep system logs retrievable for at least 12 months and retain user data after users leave, for the legal period

Service enterprises must keep system logs for verification and investigation, covering at least the user account, login and logout times, IP address, source port and the log of posted information, retrievable for at least 12 months, and must retain personal information of users and data they create (account names, usage time, payment information, access IP addresses and related data) for the period set by law after users stop using the service.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Data security, localisation and logs (Articles 25, 26; Decree 333) – Vietnam Law on Cybersecurity (No. 116/2025/QH15)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.