Vietnam Law on Cybersecurity (No. 24/2018/QH14)
Vietnam's Law on Cybersecurity (No. 24/2018/QH14), effective January 1, 2019, and its implementing Decree 13/2023/ND-CP, establish cybersecurity requirements for information systems in Vietnam. Key provisions include data localization for certain data categories, mandatory local office requirements for specified service providers, content moderation obligations, and cybersecurity incident reporting. Applies to foreign and domestic service providers operating in Vietnam.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Audit and Inspection
| Code | Title |
|---|---|
| VN-CSL-8 | Cybersecurity Inspection Readiness |
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — Protection of National Cybersecurity
| Code | Title |
|---|---|
| Art.10 | Cases When Authorization Is Not Required |
| Art.11 | Prohibition of Illegal Access |
| Art.12 | Prohibition of Illegal Interception |
| Art.9 | Authorization Requirement |
Chapter III — Prevention of Cyberspace Violations
| Code | Title |
|---|---|
| Art.16 | Computer-Related Forgery and Fraud |
| Art.17 | Content-Related Offences |
| Art.18 | Duties of Data Processors |
| Art.22 | Cooperation with Authorities |
Chapter IV — Cybersecurity for Information Systems
| Code | Title |
|---|---|
| Art.23 | Sanctions |
| Art.24 | Complaints to UAE Data Office |
| Art.25 | Preservation of Stored Data |
| Art.26 | Production Orders |
Chapter V — Cybersecurity for Activities in Cyberspace
| Code | Title |
|---|---|
| Art.26(3) | Data Storage Requirements |
| Art.28 | Real-Time Collection of Traffic Data |
| Art.29 | Registration (Repealed by 2023 Amendment) |
| Art.30 | International Cooperation |
Chapters VI-VII — Responsibilities and Implementation
| Code | Title |
|---|---|
| Art.36 | Administrative Fines |
| Art.37 | Compensation for Harm |
| Art.38 | Data Protection Impact Assessment |
| Art.41 | Data Protection Officer (Encarregado) |
| Art.43 | Amendment of Directive (EU) 2018/1972 |
Consumer Rights
| Code | Title |
|---|---|
| VN-CSL-18 | User Complaint Handling |
Content Moderation
| Code | Title |
|---|---|
| VN-CSL-12 | Account Suspension for Violations |
| VN-CSL-5 | Prohibited Content Detection and Removal |
Cross-Border Transfer
| Code | Title |
|---|---|
| VN-CSL-13 | Data Transfer Restrictions |
Data Governance
| Code | Title |
|---|---|
| VN-CSL-10 | User Data Collection and Lawful Use |
Data Residency
| Code | Title |
|---|---|
| VN-CSL-2 | Data Localisation for Vietnamese User Data |
Governance
| Code | Title |
|---|---|
| VN-CSL-1 | Scope and Applicability Determination |
| VN-CSL-20 | Records Retention and Inspection Evidence |
| VN-CSL-3 | Local Branch or Representative Office Establishment |
Identity and Access
| Code | Title |
|---|---|
| VN-CSL-4 | User Identity Verification |
Incident Response
| Code | Title |
|---|---|
| VN-CSL-9 | Incident Notification to Authorities |
Regulatory Cooperation
| Code | Title |
|---|---|
| VN-CSL-6 | Cooperation with Competent Authorities |
Resilience
| Code | Title |
|---|---|
| VN-CSL-21 | Cybersecurity Drills and Exercises |
Risk Management
| Code | Title |
|---|---|
| VN-CSL-14 | Information System Cybersecurity Assessment |
| VN-CSL-7 | Critical Information Systems Classification |
Security Controls
| Code | Title |
|---|---|
| VN-CSL-16 | Encryption and Technical Safeguards |
Security Monitoring
| Code | Title |
|---|---|
| VN-CSL-11 | Network Monitoring and Logging |
Transparency
| Code | Title |
|---|---|
| VN-CSL-17 | Public-Facing Privacy and Cybersecurity Disclosures |
Vendor Management
| Code | Title |
|---|---|
| VN-CSL-19 | Subcontractor and Third-Party Oversight |
Workforce
| Code | Title |
|---|---|
| VN-CSL-15 | Cybersecurity Personnel and Training |
Your Compliance Coverage
If you comply with Vietnam Law on Cybersecurity (No. 24/2018/QH14), you already cover:
Laos Law on Prevention and Combating Cybercrime (2015)
25%
14 controls mapped
Compare →NIS2 Directive
25%
14 controls mapped
Compare →Chile Personal Data Protection Law (Law No. 21.719)
25%
14 controls mapped
Compare →+ 636 more: ASEAN Data Management Framework (25%), UK GDPR (UK General Data Protection Regulation) (25%)
See all 639 mapped frameworks ↓Maps to 639 other frameworks
Frequently Asked Questions
What is Vietnam Law on Cybersecurity (No. 24/2018/QH14)?
Vietnam Law on Cybersecurity (No. 24/2018/QH14) is a compliance framework from Vietnam with 23 domains and 57 controls. Vietnam's Law on Cybersecurity (No. 24/2018/QH14), effective January 1, 2019, and its implementing Decree 13/2023/ND-CP, establish cybersecurity requirements for information systems in Vietnam. Key provisions include data localization for certain data categories, mandatory local office requirements for specified service providers, content moderation obligations, and cybersecurity incident reporting. Applies to foreign and domestic service providers operating in Vietnam. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Vietnam Law on Cybersecurity (No. 24/2018/QH14) have?
Vietnam Law on Cybersecurity (No. 24/2018/QH14) has 57 controls organised across 23 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapters VI-VII — Responsibilities and Implementation (5 controls), Chapter II — Protection of National Cybersecurity (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Vietnam Law on Cybersecurity (No. 24/2018/QH14) map to?
Vietnam Law on Cybersecurity (No. 24/2018/QH14) maps to 639 other compliance frameworks. The top mapping partners are Laos Law on Prevention and Combating Cybercrime (2015) (25% coverage), NIS2 Directive (25% coverage), Chile Personal Data Protection Law (Law No. 21.719) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Vietnam Law on Cybersecurity (No. 24/2018/QH14) compliance?
Start your Vietnam Law on Cybersecurity (No. 24/2018/QH14) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Vietnam Law on Cybersecurity (No. 24/2018/QH14) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required