Vietnam – Draft Cybersecurity Regulation Released

Allens Vietnam

Following the passing of the controversial Cybersecurity Law in June, the Ministry of Public Security recently released for public consultation a draft decree providing detailed guidance on this law. The draft contains a number of important clarifications of the localisation requirements applicable to foreign service providers.

Captured Service Providers

One key issue of the Cybersecurity Law is the lack of definition of 'enterprise which provides services on telecom networks and on the Internet and other value added services in cyberspace'  that is subject to localisation requirements. Under the draft decree, published on 2 November 2018, an enterprise is captured (Captured Service Provider) if it provides any of the following:

  • telecommunications services;
  • data storage and data sharing [services] in cyberspace;
  • supply of national or international domain names for service users in Vietnam;
  • e-commerce;
  • online payment;
  • payment mediation;
  • transport connection services via cyberspace;
  • social network and social media;
  • online games; or
  • email services.

Scope Of Localised Data And Storage Duration

According to the draft decree, the following types of user data (Captured Data) must be stored in Vietnam for the relevant periods:

  • For the entire operational period of the [service provider] enterprise or until it ceases providing services:
    • personal information data of service users in Vietnam, including name, date of birth, place of birth, nationality, occupation, job title, residence address, contact address, email address, telephone number, ID number, passport number, social insurance card number, credit card number, health status, medical records and biometrics.
  • For at least 36 months:
    • data generated by service users in Vietnam, including data uploaded, synchronized or input from [users'] devices; and
    • data of relationships of service users in Vietnam, including friends and groups that users connect to or interact with.

Clarification Of Data Localisation/Storing Requirements

An enterprise (whether domestic or foreign) will need to store Captured Data, and have a branch or representative office, in Vietnam, if it passes all of the following tests:

  1. it is a Captured Service Provider;
  2. it collects, exploits, analyses, processes Captured Data;
  3. it allows users to perform prohibited acts, as prescribed in Articles 8.1 and 8.2 of the Cybersecurity Law: eg dissemination of 'offending' contents, gambling, IP infringements, credit card/bank account thief, anti-state acts, acts to distort history, deny revolutionary achievements, damage national unity, offend religions, or constitute gender discrimination or racism, cyberterrorism and cyber-attacks;
  4. it violates Article 8.4, 26.2(a) or 26.2(b) of the Cybersecurity Law: eg by obstructing the cybersecurity authority's activities, failing to verify users' information and provide information to the authority, or failing to remove and prevent the sharing of information considered 'offending' under the law.

Prongs (c) and (d) of the tests appear counter-intuitive, in light of the Government's stated goals to regulate the market, as they could substantially curtail localisation requirements only to those enterprises that breach the law and allow users to breach the law at the same time. It is unclear if this is intentional or just a drafting mistake.

Enterprises that pass the tests must store data, and open a branch or representative office in Vietnam, within 12 months from the date the Minister of Public Security requests. It is not clear if the Minister will make specific requests to individual companies or there will be a market-wide deadline for this to be done.

A Captured Service Provider must also store system logs for at least 12 months.

What's Next

A number of issues remain unresolved in this draft decree:

  • the manner in which the data shall be stored: eg physical or cloud-based;
  • the use of the general term 'e-commerce' (as opposed to 'e-commerce services', such as provision of an e-commerce platform) in the draft suggests the regulation may apply to any commercial entities that conduct sale of goods and/or services on the internet/network environment;
  • whether users are limited to individual users or include corporate users (although the types of Captured Data suggest the former);
  • types of users' information that must be verified and provided to the authority; and
  • specific measures and penalties that can be applied to breaches of the law, and any judicial review process in connection with disclosure and inspection requests.

As for the consultation process, the public has until 2 January 2019 to give comments on the draft decree. If you have any questions on cybersecurity and data privacy laws, or would like to get involved in the consultation, please do not hesitate to contact us.

For Further Information, Please Contact:

Linh Bui, Partner, Ho Chi Minh City
Ph: +84 28 3822 1717
Linh.Bui@allens.com.au

Robert Fish, Partner, Ho Chi Minh City
Ph: +84 28 3822 1717
Robert.Fish@allens.com.au

Bill Magennis, Head of Vietnam, Hanoi
Ph: +84 24 3936 0990
Bill.Magennis@allens.com.au

Le Ba Thanh Chung (Chung Le), Partner, Hanoi
Ph: +84 24 3936 0990
Chung.Le@allens.com.au

 

Please Login or Register for Free now to view all updates and articles

In addition to free-to-view updates and articles, you can also subscribe to the full Legal Centrix Vietnam Service including access to:

  • Overview notes on the law
  • Thousands of high quality translations of legislation covering all key business areas
  • Legal and tax updates
  • Articles on important legal and tax issues
  • Weekly email alerts
  • Sophisticated web platform and search

Legal Centrix is trusted by top law and accounting firms.

Allens Vietnam

Allens is a leading international law firm in Vietnam. Our office was one of the first foreign law firms to be licensed after Vietnam opened up to the world in 1993. Since then, we have acted on some of Vietnam's most important large-scale projects and commercial transactions.

Our services span the full suite of legal practice areas, including:

  • Mergers and aquisitions 
  • Energy, resources and infrastructure
  • Banking and finance
  • Capital markets transactions
  • Anti-trust and merger filing
  • Construction and EPC
  • Corporate and licensing

Your trusted advisers in Vietnam

We practice both local and international law in Vietnam. Our team of international and Vietnamese lawyers is geared towards sound, efficient and timely advice. The depth of our experience in Vietnam means we can identify issues and find practical solutions, all while taking local sensitivities into account.

Our global reach and Asian network

Allens' international alliance with Linklaters ensures we can serve our clients throughout Asia and globally, wherever their business takes them, through a global network of 40 offices across 28 countries.

Click here to view the author's profile

Cookies On
Our Website
We use cookies on our website. To learn more about cookies, how we use them on our site and how to change your cookie settings please click here to view our cookie policy. By continuing to use this site without changing your settings you consent to our use of cookies in accordance with our cookie policy.