Data Protection in Vietnam

Security in Vietnam

Organizations must take necessary managerial or technical measures to ensure that the personal information shall not be lost, stolen, disclosed, modified or destroyed. Remedial measures must be taken immediately if personal information is being or is likely to be disclosed or destroyed.

A data controller must classify information based on its secrecy in order to take appropriate protection measures. Agencies and organizations that use classified and unclassified information in activities within their fields must develop regulations and procedures for processing information, and determine the content and method of recording authorized access to classified information. 

In addition, there are certain key data protection requirements under Decree 356, among others:

  • The transfer of sensitive personal data must be subject to physical security measures for storage and transmission devices, encryption measures, anonymization of personal data, and other security measures during the transfer process.
  • In cases where personal data is shared between departments within the same agency or organization for processing in accordance with the established processing purposes, the agency or organization must develop procedures to control the sharing and use of personal data in compliance with regulations; and implement measures to prevent internal personnel from unlawfully sharing personal data with third parties.
  • Personal data stored on cloud computing platforms must be encrypted both at rest and in transit, and must be subject to strict access control.
  • There are also other specific requirements in relation to AI, big data, banking/finance, metaverse, blockchain, etc. that enterprises will need to pay attention to (e.g., organizations and individuals shall apply personal data protection measures within AI systems, the metaverse, and blockchain systems, among others, including conducting annual compliance assessments with personal data protection regulations).

Continue reading

  • no results

Previous topic
Back to top