NEW REQUIREMENTS FOR CORPORATE DATA GOVERNANCE AND CYBERSECURITY COMPLIANCE
Effective 1 July 2026, the Law on Cybersecurity No. 116/2025/QH15 marks a significant shift in Vietnam’s approach to cybersecurity and data protection. While the Law continues to govern public authorities, it also substantially expands the compliance obligations of businesses. For enterprises operating digital platforms, providing online services, or processing customer data, compliance is no longer a matter of best practice—it is now a mandatory legal obligation.

One of the Law’s most significant developments is its integrated approach to personal data protection and cybersecurity. Under Article 40, information system owners are required to implement both organizational measures and technical safeguards to ensure cybersecurity throughout the entire data processing lifecycle, including the processing of personal data. In practice, businesses can no longer rely solely on privacy policies or confidentiality commitments to demonstrate compliance. Instead, they must ensure that their information systems are capable of preventing unauthorized access, securing the storage, transmission, and use of data, and promptly detecting and responding to cybersecurity threats and information security risks.
In addition, the Law requires businesses to conduct regular cybersecurity assessments, continuously monitor their information systems, apply relevant technical standards, maintain data backup mechanisms, and periodically evaluate the effectiveness of their security controls. This reflects a clear shift from a reactive approach focused on incident response to a preventive, risk-based compliance framework. Businesses are therefore expected to identify vulnerabilities, assess risks, and implement corrective measures on an ongoing basis rather than waiting until a cybersecurity incident occurs. Furthermore, organizations are required to promptly report cybersecurity incidents to the competent authorities and cooperate throughout the investigation and response process, recognizing that a single incident may affect multiple stakeholders and, in certain cases, even national security.
Against this backdrop, businesses should look beyond investing solely in technical infrastructure and establish comprehensive governance frameworks for data management, cybersecurity monitoring, and incident response in line with the requirements of the Law. Delayed compliance or failure to meet these legal obligations may expose organizations to increased legal and operational risks, disrupt business continuity, and undermine their reputation and customer trust. Conversely, taking proactive steps to strengthen cybersecurity governance and achieve compliance from the outset will not only reduce legal and operational risks but also enhance corporate governance, reinforce stakeholder confidence, and create a sustainable competitive advantage in Vietnam’s rapidly evolving digital economy. the digital economy.