Safeware Glasswall APAC Partner
Book a demo

Regulatory landscape · Southeast Asia

Vietnam: file security and audit obligations

Vietnam combines a cybersecurity law with data localisation expectations and a personal data protection decree, making data residency the dominant architectural constraint.

At a glance

How Vietnam regulates file security

  • 01

    Regime

    Cybersecurity Law with localisation expectations plus a personal data protection decree

  • 02

    File security

    Sectoral technical requirements; localisation constrains architecture

  • 03

    Audit and evidence

    Incident reporting to the Ministry of Public Security; PDPD obligations

Overview

The regulatory picture

Vietnam's framework is shaped more by data residency than by prescriptive technical controls. The Cybersecurity Law 2018 established obligations around content, incident cooperation with the Ministry of Public Security, and data localisation for certain service providers. Decree 13/2023/ND-CP on Personal Data Protection (PDPD) introduced consent, impact assessment and cross-border transfer requirements, with impact assessment dossiers filed with the Ministry of Public Security.

For file security specifically, the practical consequence is architectural: where localisation or transfer-assessment requirements apply, file processing has to happen inside Vietnam or under a documented transfer basis. This is a market where an on-premises deployment is frequently the only workable answer. We track headline developments here rather than claiming deep coverage.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Decree 13/2023/ND-CP on Personal Data ProtectionMPSIn forceDirect
Cybersecurity Law 2018MPSIn forceIndirect

MPS

Decree 13/2023/ND-CP on Personal Data Protection

Establishes consent requirements, personal data processing impact assessments and cross-border transfer dossiers filed with the Ministry of Public Security.

Why it matters for file security. Cross-border transfer assessment applies to personal data moving out of Vietnam, including inside documents. Where a transfer basis is not available, file processing must remain in-country.

How Glasswall addresses it. Meteor deploys on-premises inside Vietnam, so file processing can satisfy residency expectations without a cross-border transfer basis. Data loss prevention reduces the personal data carried in documents where transfer is unavoidable.

Content disarm and reconstructionData loss preventionGlasswall Meteor / Glasswall Halo

Source: MPS

MPS

Cybersecurity Law 2018

Establishes obligations around incident cooperation with authorities and data localisation for certain categories of service provider.

Why it matters for file security. Localisation obligations determine where file-processing infrastructure may sit, which is an architectural constraint before it is a control question.

How Glasswall addresses it. Where localisation applies, an on-premises Meteor deployment keeps file processing and its verdict records inside Vietnam.

Content disarm and reconstructionPer-file verdict recordGlasswall Meteor

Source: MPS

Latest developments

What has changed in Vietnam

Most recent first.

  1. In forceHigh impact

    Decree 330/2026/ND-CP: administrative sanctions for cybersecurity and personal data violations

    Vietnam issued Decree No. 330/2026/ND-CP on 19 August 2026, effective the same day, establishing administrative penalties for violations of the Law on Personal Data Protection (and implementing Decree 356/2025/ND-CP) and the Law on Cybersecurity. Headline fines: up to VND 100 million for data protection impact assessment violations, VND 80 million for breach-notification failures, and, for unlawful cross-border transfers of personal data, up to 5% of preceding-year revenue or VND 3 billion.

    Why it matters for file security. The cross-border penalty is the one that reaches file handling directly: documents are how personal data usually leaves a country, and a revenue-based fine attaches a board-level number to uncontrolled file transfer out of Vietnam. Breach-notification penalties also raise the value of being able to establish quickly which files an incident touched.

    How Glasswall addresses it

    An on-premises Meteor deployment keeps file processing and its verdict records inside Vietnam, so no cross-border transfer basis is needed for the processing itself. Data loss prevention reduces the personal data carried in documents that do move, and the per-file verdict record shortens the work of establishing what an incident touched when a notification decision is on the clock.

    Content disarm and reconstructionData loss preventionPer-file verdict recordGlasswall Meteor / Glasswall Halo

    • banking
    • telco
    • healthcare
    • government

    Source: Tilleke & Gibbins

Scope

About this page

This page is a working reference for organisations operating in Vietnam.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Vietnam?