Law / Vietnam

Vietnam

14 of 21 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 20 September 2026.

When they take effect14 of 14 carry a date.
2017: 2 instruments (2 in force) ’17 2018: 0 instruments 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 11 instruments (11 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 4
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 4 in force

Research summary (325 words)

Vietnam's first comprehensive AI statute is the Law on Artificial Intelligence, Law No. 134/2025/QH15, passed by the 15th National Assembly at its 10th session on 10 December 2025 and in force since 1 March 2026.

It applies to Vietnamese and foreign agencies, organizations, and individuals involved in AI activities in Vietnam, excluding activities serving national defense, security, and cipher purposes exclusively, and sets a three-tier risk classification (high, medium, low) with escalating notification and conformity-assessment duties, a transparency and labeling duty for AI-generated content, and a closed list of prohibited practices.

Decision No. 367/QD-TTg, signed 28 February 2026 and published 3 March 2026, approves the government's implementation plan assigning tasks to line ministries and provincial People's Committees; it is a government-internal coordination instrument rather than a source of duties on a developer or deployer.

Several implementing details, including the official list of high-risk AI systems, the administrative-sanction decree, and the technical form of required labels, are left to Government regulations not yet issued as of this review.

Article 12 carries the Law's incident duty, recorded below: a developer or provider must urgently remedy a serious incident and notify the competent state agency at the same time, and a deployer or user must record it, notify promptly, and coordinate in the remediation, all through the one-stop artificial intelligence portal.

The Law states no number of hours or days for that report, using only kịp thời (promptly) and khẩn trương (urgently), and Article 12(5) leaves the deadline to a Government decree. Decree No. 142/2026/ND-CP has been issued to implement the Law and its promulgated text is not read here, so the deadline it sets is not stated.

The article text here rests on a private secondary publisher (LuatVietnam), which states it distributes the English translation of the Official Gazette text published by the Vietnam News Agency, and is corroborated on the commencement date and Decision No. 367/QD-TTg by the Ministry of Science and Technology's own government portal.

AI prohibited practices

Law on Artificial Intelligence, prohibited practices

Law No. 134/2025/QH15, art. 7Unofficial English translation of the Official Gazette text (LuatVietnam), not the Government Portal's or Official Gazette's own text

In force 7 months, effective 1 March 2026. Binds public and private bodies.

What this law does

Article 7 bars developing, providing, deploying, or using an AI system to use forged elements or simulations of real people or events to intentionally and systematically deceive or manipulate human perceptions or behaviour where this causes serious harm, to exploit weaknesses of a vulnerable group such as children, the elderly, people with disabilities, or people with limited cognitive or civil-act capacity, or to create or disseminate fake content capable of posing a serious danger to national security, public order, or social safety.

It separately bars collecting, processing, or using data to develop, train, test, or operate an AI system in a way that contravenes Vietnam's data, personal data protection, intellectual property, or cybersecurity law, and bars obstructing, disabling, or distorting the human-oversight mechanisms the Law requires over an AI system.

What it requires

AI risk obligations

Law on Artificial Intelligence, incident management and reporting obligation

Law No. 134/2025/QH15, art. 12Unofficial English translation of the Official Gazette text (LuatVietnam), not the Government Portal's or Official Gazette's own text

In force 7 months, effective 1 March 2026. Binds public and private bodies.

What this law does

Article 12 requires every developer, provider, deployer and user of an artificial intelligence system to keep the system safe, secure and reliable, and to promptly detect and remedy an incident capable of harming people, property, data or social order.

When a serious incident occurs in an artificial intelligence system, the developer and provider must urgently apply technical measures to remedy, suspend or recall the system, and must simultaneously notify the competent state agency of the incident. The deployer and the user of the system must record the incident, notify it promptly, and coordinate with one another during the remediation process.

The competent state management agency receives, verifies and guides the remediation, and may require the system to be suspended, recalled or reassessed when necessary. Reporting and remediation of the incident is carried out through the one-stop artificial intelligence portal.

Article 12 does not itself state a reporting deadline; instead it directs the Government to specify the reporting procedure and the responsibilities of the agencies, organisations and individuals involved, calibrated to the severity of the incident and the scope of its impact. Article 12 addresses the developer, provider, deployer and user of the system and the competent state agency; it does not itself direct any notice to a person affected by the incident.

Decree 142/2026/ND-CP, reported as covering the Law's risk-classification duties and the one-stop portal, has been issued to implement the Law, and its promulgated text is not read here, so the deadline it sets is not stated.

What it requires

Law on Artificial Intelligence, risk classification and conformity assessment

Law No. 134/2025/QH15, arts. 9-10, 13-14Unofficial English translation of the Official Gazette text (LuatVietnam), not the Government Portal's or Official Gazette's own text

In force 7 months, effective 1 March 2026. Binds public and private bodies.

What this law does

Article 9 classifies an AI system as high, medium, or low risk based on its potential to cause significant harm to rights, safety, security, or public interest, its capacity to confuse users about whether they are dealing with an AI system, and criteria the Government is to detail further, including the field of use and the scale and range of its impact.

Article 10 requires a provider to classify its own system before putting it into service, to prepare a classification dossier for a medium-risk or high-risk system, and to notify the classification result to the Ministry of Science and Technology through the one-stop AI portal before deployment; a deployer inheriting a provider's classification must re-classify if a modification creates a new or higher risk.

Articles 13 and 14 require a high-risk system to undergo conformity assessment, by a registered assessment organization or by the provider itself depending on the system, before being put into service or after a significant change, and require the assessment result to be maintained throughout operation as a condition of continued use.

Decision No. 367/QD-TTg, the government's implementation plan for the Law, is preparing a Prime Ministerial decision listing high-risk AI systems by five criteria, but this list had not been issued as of this review.

What it requires

AI transparency

Law on Artificial Intelligence, transparency obligation

Law No. 134/2025/QH15, art. 11Unofficial English translation of the Official Gazette text (LuatVietnam), not the Government Portal's or Official Gazette's own text

In force 7 months, effective 1 March 2026. Binds public and private bodies.

What this law does

Article 11 requires a provider to design and operate an AI system that interacts directly with humans so that a user can recognise they are interacting with such a system, unless the law provides otherwise, and to mark AI-generated audio, image, and video content in a machine-readable format under forthcoming Government regulations.

A deployer must clearly notify the public when providing AI-generated or AI-edited text, audio, images, or video that could cause confusion about the authenticity of an event or a person, and must attach an easily recognisable label to AI-generated or AI-edited content that simulates or replicates a real person's appearance or voice or recreates a real event, with a lighter labeling standard for cinematographic, artistic, or creative works so the label does not obstruct enjoyment of the work.

Both providers and deployers must keep this transparency information current throughout the life of the system, product, or content.

What it requires

Privacy law5 instruments, 5 in force

Research summary (148 words)

Vietnam's first standalone, comprehensive personal-data statute is the Law on Personal Data Protection, Law No. 91/2025/QH15, passed by the 15th National Assembly at its 9th session on 26 June 2025 and in force since 1 January 2026, replacing Decree 13/2023/ND-CP, which was itself only a government decree rather than a National Assembly law.

The Law's number is 91/2025/QH15, as the Government Portal's page for the enactment and the Ministry of Public Security's commencement announcement both state; the number 34/2025/QH15 sometimes attached to it names a different enactment. The article-level text rests on a private secondary publisher's English translation rather than on the government's own signed PDF.

Article 31's biometric data definition names no facial or voice examples, resting entirely on general physical-attribute language, so its exact reach to a recording-derived identifier is unresolved. A companion implementing decree, Decree 356/2025/ND-CP, took effect alongside the Law on the same date.

Biometric privacy

Law on Personal Data Protection, biometric and location data protection

Law No. 91/2025/QH15, Article 31Government Portal (chinhphu.vn) citation

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Article 31 defines biometric data as data on physical attributes and unique and stable biological characteristics of a person used to identify that person, and requires an organization, agency, or individual collecting or processing biometric data to apply physical security measures for storage and transmission devices, limit access, maintain a monitoring system to detect infringement, and comply with relevant laws and international standards; a processor causing damage through biometric-data processing is liable.

Article 31 names no facial, voice, or fingerprint example, resting entirely on the general physical-attribute language; whether the definition reaches an identifier derived from a photo, video, or audio recording is unresolved. This provision functions as heightened, category-wide protection rather than a named consent-at-capture rule distinct from the Law's general Article 8 consent duty.

What it requires

Breach notification

Law on Personal Data Protection, breach notification

Law No. 91/2025/QH15, Article 23Government Portal (chinhphu.vn) citation

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Article 23 requires the personal data controller, the personal data controlling and processing party, or a third party to notify the agency in charge of personal data protection within 72 hours after detecting a violation likely to cause harm to national defense and security and social order and safety, or to infringe upon the life, health, honor, dignity, or property of the personal data subject.

Where a personal data processor detects a violation, it must promptly notify the controller or the controlling and processing party.

What it requires

Comprehensive regime

Law on Personal Data Protection, comprehensive regime

Law No. 91/2025/QH15, passed by the 15th National Assembly, 9th session, 26 June 2025, in force 1 January 2026Government Portal (chinhphu.vn) citation

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

The Law on Personal Data Protection (Law No. 91/2025/QH15) is Vietnam's first standalone, comprehensive personal-data statute, replacing Decree 13/2023/ND-CP, which was itself Vietnam's first general personal-data instrument but only a government decree rather than a National Assembly law. A companion implementing decree, Decree 356/2025/ND-CP, took effect alongside the Law on the same date; its provisions are not described here.

The Law's commencement date is confirmed via the Ministry of Public Security's own portal, a government source; the government's own signed PDF of the Law does not yield extractable text, so the substantive article text here comes from a private secondary publisher's English translation (LuatVietnam) rather than from the government's own text, and is not verified against the primary PDF.

A citation of this same enactment as Law No. 34/2025/QH15 is incorrect, per the Government Portal's own page title and the Ministry of Public Security's announcement.

What it requires

Cross border transfer

Law on Personal Data Protection, cross-border transfer

Law No. 91/2025/QH15, Article 20Government Portal (chinhphu.vn) citation

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

Article 20 enumerates the cases in which cross-border transfer of personal data is permitted; whether its conditions include an adequacy standard, a government approval requirement, or a data-localization element is not established.

A separate penalties article confirms a materially strict enforcement posture: the maximum fine for an organization violating cross-border transfer regulations specifically is 5 percent of the organization's prior-year revenue, distinct from and higher than the Law's general violation fine tier.

What it requires

Enforcement supervision

Law on Personal Data Protection, enforcement and data subject rights

Law No. 91/2025/QH15, enforcement and data subject rights provisionsGovernment Portal (chinhphu.vn) citation

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

The Law names an agency in charge of personal data protection as the enforcement authority, without independently confirming the specific body's name, though the Ministry of Public Security's role publicizing the Law's commencement suggests it sits under that ministry.

Administrative fines confirmed directly reach up to 5 percent of the prior year's organizational revenue for cross-border transfer violations specifically, with a separate, lower general fine tier referenced elsewhere in the same penalties article and not read in full.

A data-subject-rights clause confirms individuals may request the provision and deletion of their personal data, restriction of processing, and may object to processing, and separately may file complaints and denunciations, initiate lawsuits, and request compensation for damage in accordance with law, arming a private plaintiff.

What it requires

Scraping law1 instrument, 1 in force

Research summary (264 words)

Vietnam has no scraping-specific statute, so general law governs each dimension separately, and several dimensions are not established in the primary text reached here.

The Law on Cybersecurity (Law No. 24/2018/QH14) prohibits illegally accessing a telecom network, the Internet, a computer network, an information system, or a database of another person, and this prohibition does not on its face require defeating a security measure the way Kenya's or the United States' computer-misuse statutes do, so whether reading a public, unauthenticated page falls within it is unsettled rather than confirmed either way.

No primary source establishing Vietnam's position on terms-of-service enforceability (browsewrap or clickwrap), a text-and-data-mining or fair-use exception under the amended Intellectual Property Law, a sui generis database right, an unfair-competition or misappropriation doctrine reaching scraping, or the legal weight of a robots.txt directive is described here; the amended Intellectual Property Law (Law No. 07/2022/QH15) is reported in secondary sources to have added text-and-data-mining provisions, but its primary text is not reached.

Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15), researched under this corpus's privacy topic, applies to the collection, use, and disclosure of personal data in Vietnam, and whether it exempts information the data subject has made publicly available is not confirmed in the primary text.

The Law on Cybersecurity separately requires a cyberspace service provider collecting, using, analysing, or processing Vietnamese users' personal information to store that data in Vietnam and, if the provider is a foreign enterprise, to maintain a branch or representative office in Vietnam, a data-localization duty attaching to personal data rather than to the act of scraping.

Computer misuse

Law on Cybersecurity, unauthorized access prohibition

Law No. 24/2018/QH14 (Law on Cybersecurity), art. 8(3), art. 9Unofficial English translation of Law No. 24/2018/QH14 (economica.vn), not the official Vietnamese-language gazette text

In force since 1 January 2019. Binds public and private bodies.

What this law does

Article 8(3) strictly prohibits producing or using tools to obstruct or disrupt the operation of a telecom network, the Internet, a computer network, an information system, or an e-facility, distributing software that harms such a system, or illegally accessing a telecom network, the Internet, a computer network, an information system, or a database of another person.

The prohibition's own wording turns on access being illegal rather than on defeating a specific security measure, so whether it reaches a scraper reading a public, unauthenticated page is unsettled rather than confirmed either way, and no reported case addresses the point.

Article 9 provides that a breach of the Law is, depending on its nature and seriousness, disciplined, subject to an administrative penalty, or criminally prosecuted, with compensation owed for any loss caused, but the Law itself states no fine amount or imprisonment term for this prohibition, leaving those to administrative decrees and the Penal Code.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (599 words)

Vietnam's product-security and cyber-resilience posture now rests on a single consolidated statute, the Law on Cybersecurity, Law No. 116/2025/QH15, passed by the National Assembly on 10 December 2025 and in effect since 1 July 2026, which expressly repeals both of the two statutes it replaces, the 2015 Law on Cyberinformation Security (No. 86/2015/QH13) and the 2018 Law on Cybersecurity (No. 24/2018/QH14), on its own effective date.

Article 8 classifies every information system into five statutory levels by the damage an incident or a cybersecurity-law violation could cause, and Article 10 grades the manager's protection duty to that level: a level 1 or level 2 manager must perform every Article 10(1) task (determine the system's level, assess and manage its risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise awareness) and may choose which Article 10(2) measures to apply; a level 3 or level 4 manager whose system is not on the Prime Minister's list of information systems critical to national security must additionally, and mandatorily, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents, plus file a level-classification dossier and obtain approval before putting the system into operation.

Decree No. 331/2026/ND-CP, issued 19 August 2026 to detail Article 8(2), sets the actual classification criteria and procedure a manager applies to find its level.

A system the Prime Minister has placed on the list of information systems critical to national security under Article 9, a government designation rather than a declared activity, carries the full Article 10(1) and 10(2) obligation set plus its own appraisal, certification, and annual self-inspection regime under Article 11, and is recorded here as background rather than raised against a declared activity, the treatment this profile gives Japan's designated critical-infrastructure operator and Singapore's provider-owned critical information infrastructure.

Article 40(1)(c) separately requires any information system manager, at any level, to report a cybersecurity incident to the specialised cybersecurity protection force of the Ministry of Public Security or the Ministry of National Defence, and Article 41 layers a parallel duty on any domestic or foreign enterprise providing services on a telecommunications network, the Internet, or another value-added service in cyberspace in Vietnam: warn users of cybersecurity risks and give preventive guidance, keep an emergency response plan for cybersecurity weaknesses, risks and incidents, implement that plan and report an incident to the specialised force the moment it occurs, and apply technical measures to secure data processing, including personal-data processing.

Decree No. 330/2026/ND-CP, the administrative-sanctions decree issued the same day as Decree No. 331, prices both duty sets in Vietnamese dong, doubling the stated figure for an organisation.

The Law's own Article 25 imposes a further set of duties on the same enterprise class, real-name authentication of a user's digital account, a 24-hour clock (3 hours in an emergency) to hand a user's information to the specialised force, a 24-hour clock (6 hours in an emergency) to remove content that clock names, and in-country storage of personal information and service-usage data with a foreign branch or representative office requirement; these are content-moderation and data-localisation duties rather than a security-posture requirement and sit outside this topic, the same seam this corpus draws in every jurisdiction.

Vietnam's comprehensive data-protection statute, the Law on Personal Data Protection (Law No. 91/2025/QH15), carries this jurisdiction's breach-notification duty as its own privacy-topic row, and the Penal Code's unauthorised-access offence, an intruder's liability rather than an operator's, is this jurisdiction's scraping-topic row; neither is restated here.

Security baseline statutes

Cybersecurity Law, Information System Classification and Protection Measures

Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10English translation, LuatVietnam, Law No. 116/2025/QH15

In force 84 days, effective 1 July 2026. Binds public and private bodies.

What this law does

Article 8 sorts every information system into one of five levels by the damage a cybersecurity incident or violation could cause, and Article 10 grades a manager's protection duty to that level, reaching any manager, state or private, of a level 1 to level 4 system; a system on the Prime Minister's list of information systems critical to national security carries a fuller, separately gated regime under Articles 9 and 11.

Decree No. 331/2026/ND-CP, effective 19 August 2026, sets the classification criteria and the approval procedure the Law's Article 8(2) delegates to the Government.

What it requires

Vulnerability and incident reporting

Cybersecurity Law, Incident Response and Reporting Duties

Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 40(1)(c), 41(2)-(4)English translation, LuatVietnam, Law No. 116/2025/QH15

In force 84 days, effective 1 July 2026. Binds public and private bodies.

What this law does

Article 40(1)(c) requires any information system manager, at any level, to report a cybersecurity incident to the specialised cybersecurity protection force.

Article 41 layers a parallel duty on any domestic or foreign enterprise providing a telecommunications, Internet, or other value-added cyberspace service in Vietnam: keep an emergency response plan for cybersecurity weaknesses, risks and incidents, implement it and report an incident the moment it occurs, and apply technical measures to secure data processing, including personal-data processing.

What it requires

Age gating law1 instrument, 1 in force

Research summary (129 words)

Vietnam has no adult-content age-verification statute, no social-media minor-access statute, and no app-store-level device-based age-verification requirement established in the primary text reached here.

The Law on Children (Law No. 102/2016/QH13), in force since 1 June 2017, defines a child as a person below the age of sixteen and, at Article 54, places a general duty on any agency, organization, or individual that manages or provides information and communications products and services in the Internet environment to apply measures ensuring safety and privacy for children, with the Government left to detail the specific measures required.

The Law's own text sets no age-verification mechanism, no numeric threshold for a covered service, and no specific technical or design requirement; those specifics, if any, sit in Government regulations that are not described here.

Age-appropriate design code

Law on Children, responsibility to protect children in the internet environment

Law No. 102/2016/QH13, Article 54Unofficial English translation of Law No. 102/2016/QH13 (economica.vn)

In force since 1 June 2017. Binds public and private bodies.

What this law does

Article 54 requires an agency, organization, or individual that manages or provides information and communications products and services, or organizes activities, in the Internet environment to apply measures ensuring safety and privacy for children, defined by Article 1 as a person below the age of sixteen; clause 3 leaves the Government to detail the article's specific requirements, which are not independently confirmed here.

Article 87 assigns the Ministry of Information and Communications responsibility to manage and guide regulations on the press, publication, telecommunications, Internet, and other information channels involving children, and to protect children in the environment of the Internet, computer networks, and telecommunication networks.

Article 105 provides that a violator of the Law is disciplined, administratively sanctioned, or examined for penal liability depending on the nature and severity of the violation.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (155 words)

Vietnam has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; instead, the Press Law (Law No. 103/2016/QH13), in force since 1 January 2017, directly regulates a distinct entity type it calls a news aggregation website.

Article 36 requires such a website to quote journalistic news sources verbatim and accurately, to show the author's name, the press agency's name, and the time of publication or transmission, to keep its aggregated content within the Law's content prohibitions, to operate an information management and monitoring process, to remove aggregated content as soon as the quoted source removes it, and to comply with further Government regulations on establishing a news aggregation website.

No hot-news or misappropriation doctrine distinct from this statutory scheme has been located, and no statute or reported case addresses whether a hyperlink is itself a communication to the public, whether framing changes the answer, or whether a machine-readable text-and-data-mining reservation binds an aggregator's indexing.

Snippet reproduction

Press Law, news aggregation website

Law No. 103/2016/QH13, Article 36Unofficial English translation of Law No. 103/2016/QH13 (economica.vn)

In force since 1 January 2017. Binds public and private bodies.

What this law does

Article 36 requires a news aggregation website to quote journalistic news sources verbatim and accurately, and to show the name of the author, the name of the press agency, and the time of publication or transmission of the aggregated information.

The aggregated content must not violate the Law's content prohibitions at clause 13, Article 9, and the establishing agency or organization must develop an information management process to examine, monitor, and remove prohibited content on its own initiative or on the request of a competent state agency.

An aggregator must remove an aggregated content item as soon as the quoted source itself removes that content, and the establishment of a news aggregation website by an agency, organization, or enterprise must further comply with regulations of the Government, whose content is not described here.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.