Regulatory landscape · Southeast Asia
Vietnam: file security and audit obligations
Vietnam combines a cybersecurity law with data localisation expectations and a personal data protection decree, making data residency the dominant architectural constraint.
At a glance
How Vietnam regulates file security
- 01
Regime
Cybersecurity Law with localisation expectations plus a personal data protection decree
- 02
File security
Sectoral technical requirements; localisation constrains architecture
- 03
Audit and evidence
Incident reporting to the Ministry of Public Security; PDPD obligations
Overview
The regulatory picture
Vietnam's framework is shaped more by data residency than by prescriptive technical controls. The Cybersecurity Law 2018 established obligations around content, incident cooperation with the Ministry of Public Security, and data localisation for certain service providers. Decree 13/2023/ND-CP on Personal Data Protection (PDPD) introduced consent, impact assessment and cross-border transfer requirements, with impact assessment dossiers filed with the Ministry of Public Security.
For file security specifically, the practical consequence is architectural: where localisation or transfer-assessment requirements apply, file processing has to happen inside Vietnam or under a documented transfer basis. This is a market where an on-premises deployment is frequently the only workable answer. We track headline developments here rather than claiming deep coverage.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Decree 13/2023/ND-CP on Personal Data Protection | MPS | In force | Direct |
| Cybersecurity Law 2018 | MPS | In force | Indirect |
MPS
Decree 13/2023/ND-CP on Personal Data Protection
Establishes consent requirements, personal data processing impact assessments and cross-border transfer dossiers filed with the Ministry of Public Security.
Why it matters for file security. Cross-border transfer assessment applies to personal data moving out of Vietnam, including inside documents. Where a transfer basis is not available, file processing must remain in-country.
How Glasswall addresses it. Meteor deploys on-premises inside Vietnam, so file processing can satisfy residency expectations without a cross-border transfer basis. Data loss prevention reduces the personal data carried in documents where transfer is unavoidable.
Content disarm and reconstructionData loss preventionGlasswall Meteor / Glasswall Halo
MPS
Cybersecurity Law 2018
Establishes obligations around incident cooperation with authorities and data localisation for certain categories of service provider.
Why it matters for file security. Localisation obligations determine where file-processing infrastructure may sit, which is an architectural constraint before it is a control question.
How Glasswall addresses it. Where localisation applies, an on-premises Meteor deployment keeps file processing and its verdict records inside Vietnam.
Content disarm and reconstructionPer-file verdict recordGlasswall Meteor
Latest developments
What has changed in Vietnam
Most recent first.
-
Decree 330/2026/ND-CP: administrative sanctions for cybersecurity and personal data violations
Vietnam issued Decree No. 330/2026/ND-CP on 19 August 2026, effective the same day, establishing administrative penalties for violations of the Law on Personal Data Protection (and implementing Decree 356/2025/ND-CP) and the Law on Cybersecurity. Headline fines: up to VND 100 million for data protection impact assessment violations, VND 80 million for breach-notification failures, and, for unlawful cross-border transfers of personal data, up to 5% of preceding-year revenue or VND 3 billion.
Why it matters for file security. The cross-border penalty is the one that reaches file handling directly: documents are how personal data usually leaves a country, and a revenue-based fine attaches a board-level number to uncontrolled file transfer out of Vietnam. Breach-notification penalties also raise the value of being able to establish quickly which files an incident touched.
How Glasswall addresses it
An on-premises Meteor deployment keeps file processing and its verdict records inside Vietnam, so no cross-border transfer basis is needed for the processing itself. Data loss prevention reduces the personal data carried in documents that do move, and the per-file verdict record shortens the work of establishing what an incident touched when a notification decision is on the clock.
Content disarm and reconstructionData loss preventionPer-file verdict recordGlasswall Meteor / Glasswall Halo
- banking
- telco
- healthcare
- government
Elsewhere in the region
Other APAC territories
Scope
About this page
This page is a working reference for organisations operating in Vietnam.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.



