On a desk in Ho Chi Minh City, where only guidelines once lay, three new statutes now sit, marking a shift from the permissive ethos of yesteryears to a more regulated investment climate in Vietnam.
From Fragmentation to Statute
For years, Vietnam's digital governance was scattered across decrees, circulars, and sector-specific notices. A fintech firm might answer to the State Bank on payment data, an e-commerce platform to the Ministry of Industry and Trade on consumer records, and a hospital to the Ministry of Health on patient files, all under different guidance. That patchwork is now being overlaid with statutes passed at the National Assembly level.
The shift began in mid-2025. On 14 June 2025, the National Assembly enacted the Law on Digital Technology Industry (DTI Law), with several articles taking effect on 1 July 2025 and the remainder on 1 January 2026. The Law on Data entered force on 1 July 2025. On 26 June 2025, the National Assembly passed the Law on Personal Data Protection (PDPL), Law No. 91/2025/QH15, which took effect on 1 January 2026. Decree No. 356/2025/ND-CP, issued on 31 December 2025, guides the PDPL and replaced the earlier Decree 13/2023/ND-CP on personal data protection.
The Law on Artificial Intelligence, No. 134/2025/QH15, took effect on 1 March 2026. Decree No. 142/2026/ND-CP, issued on 30 April 2026 and effective from 1 May 2026, details risk classification, conformity assessment, and operational requirements. Decree No. 100/2026/ND-CP, issued in April 2026, updates intellectual-property rules to address AI-generated objects, IP databases, and accelerated examination. The Future of Privacy Forum observed in a January 2026 brief that the PDPL and Decree 356 finally give Vietnam a unified statutory framework where data-protection rules had previously been spread across many instruments.
The practical effect is that companies can no longer treat digital compliance as an afterthought. The laws overlap—data protection rules intersect with cybersecurity obligations, AI rules sit inside the digital-industry framework, and IP rules now address machine-generated output. A company entering Vietnam must map which statutes apply to each part of its operation rather than relying on a single compliance checklist.
Personal Data: Fines Now Follow Revenue
The PDPL introduces penalties that scale with business size. For unauthorised cross-border transfers of personal data, companies face fines of up to 5% of their preceding-year revenue in Vietnam, according to Vietnam Law Magazine and CMS Legal. For buying or selling personal data without permission, the fine can reach 10 times the illegal gains. Other violations carry penalties of up to VND 3 billion (roughly USD 112,000).
The enforcement backdrop explains the severity. The Ministry of Public Security reported more than 30 cases of illegal purchase, sale, and theft of personal data between 2023 and 2025, involving roughly 160 million data files across healthcare, education, banking, finance, electricity, insurance, and telecommunications. Vietnam Law Magazine covered these figures in May 2026.
Under the PDPL, data subjects have the right to access, correct, delete, and withdraw consent for their personal data. Consent must be informed, explicit, and separate from other terms and conditions. Controllers must notify the personal data protection agency within 72 hours of detecting a violation that may harm national defence, security, public order, or the life, health, honour, dignity, or property of data subjects. Breaches involving location or biometric data also require notifying affected individuals within 72 hours, per CMS Legal's September 2025 analysis.
Decree 356 clarifies that large-scale processing—defined as involving 100,000 data subjects or more—triggers obligations to appoint a data protection department or officer, even for micro and small enterprises that might otherwise be exempt. For cross-border transfers, the PDPL requires a data-processing impact assessment to be submitted to the Ministry of Public Security within 60 days of the first transfer. That requirement affects regional headquarters, shared-service centres, and any business using overseas cloud platforms to store Vietnamese personal data.
For investors, this means due diligence on data practices is no longer a box-ticking exercise. Any target company that handles Vietnamese personal data—employee records, customer databases, or user logs—needs clear records of consent, cross-border transfer assessments, and incident-response procedures. The cost of building those systems falls on the company, but it also creates a market for compliance, legal-tech, and cybersecurity services.
AI: Risk Classification Before Deployment
The AI Law and Decree 142/2026/ND-CP impose a risk-based regime. Providers must classify AI systems as high, medium, or low risk before putting them into operation. High-risk systems must undergo a conformity assessment. The Ministry of Science and Technology manages a one-stop portal and a national database of AI systems, and provides electronic self-assessment tools. Viet An Law and DataGuidance reported these provisions in May 2026.
The DTI Law sets out seven core principles for AI development, provision, and use: a human-centered approach, transparency, accountability, explainability, cybersecurity and safety, data protection, and effective risk management throughout the AI lifecycle. High-risk AI systems are identified by impact level, field of use, and scope and scale. Medium-risk systems require notification to the ministry before operation, while low-risk systems are encouraged but not required to publish basic information.
Deployers—not just developers—must coordinate with providers to review and reclassify a system when changes in deployment, integration, or purpose introduce new or higher risks. This matters for startups that build applications on top of third-party APIs from OpenAI, Claude, or Gemini, because integration can alter the risk profile of the final product.
From 1 May 2026, deployers must label audio, images, or videos generated or edited by AI if they simulate a real person's appearance or voice, or recreate factual events. Exemptions include technical quality improvements, text processing such as translation or summarisation, internal use without public release, and research in controlled environments. Severe AI incidents must be reported within 72 hours. The decree also establishes an AI sandbox and a National AI Development Fund to invest in AI infrastructure, human resources, core technology, and innovative startups.
The rules apply to foreign organisations and individuals participating in AI activities within Vietnam, not just domestic companies. Fintech, health-tech, and ed-tech ventures face particular scrutiny, because algorithms in those sectors often score, screen, or make decisions about individuals.
Digital Industry Incentives
The same statutes that raise compliance barriers also offer incentives. The DTI Law designates AI system development, semiconductor chip research and development, and AI data centre construction as sectors eligible for special investment incentives. These include corporate income tax relief, land-use preferences, customs support, and direct state-budget support for factory construction and equipment, according to Vision Associates and Tilleke & Gibbins.
The law also authorises concentrated digital technology zones to host manufacturing, laboratories, and testing facilities, and it requires regular monitoring of industry indicators such as enterprise counts, R&D projects, employment, and export performance. Public procurement tilts toward domestic digital products and services, giving Vietnamese technology firms a steady demand base.
Decree 100/2026/ND-CP adds an intellectual-property dimension by creating frameworks for IP inventories, valuation, and new rules on IP objects created with AI, including accelerated substantive examination. It also introduces security-control requirements for inventions before they are filed abroad, reflecting Vietnam's effort to align IP protection with national-security considerations.
The policy direction is consistent with Vietnam's broader industrial strategy: attract advanced manufacturing and digital services, but require them to operate within a defined regulatory perimeter. The country wants the semiconductor packaging plant and the AI data centre; it also wants to know where the data is stored, who owns the algorithm, and how the system is tested.
What Investors Should Watch
First, cross-border data transfers now carry explicit compliance costs. Any company moving Vietnamese personal data abroad must prepare impact-assessment reports and submit them to the Ministry of Public Security within 60 days of the first transfer. That requirement affects regional headquarters, shared-service centres, and any business using overseas cloud platforms.
Second, AI investments need legal review before launch. Risk classification, conformity assessment, and labeling obligations apply at the product level, not just the corporate level. A model that is low-risk in one jurisdiction may be medium- or high-risk in Vietnam depending on its use case. Investors should ask portfolio companies for written risk classifications and, where relevant, conformity documentation.
Third, the incentive framework creates openings in compliance services, data-centre infrastructure, semiconductor packaging, and IP management. The companies best positioned are those that can combine technical capability with documented governance. A clean data-handling record and a labelled AI system are no longer just ethical preferences; they are prerequisites for public-sector contracts and large corporate customers.
Fourth, ownership of AI-generated output is becoming a contractual issue. Decree 100/2026/ND-CP begins to address AI-created IP objects, but the boundary between human and machine authorship remains unsettled in practice. Investors in content, software, and design ventures should review employment and contractor agreements to clarify who owns machine-assisted work product.
Vietnam is not regulating digital activity for its own sake. It is building a legal architecture that matches its industrial ambitions: a country that wants to move up the value chain in semiconductors, AI, and data services while keeping personal data and critical systems under domestic oversight. Investors who accept that trade-off will find the rules clearer than before; those who ignore them will find the penalties far more expensive.
Implementation Timeline and Gaps
The statutes do not all move at the same speed. The Law on Data and the relevant articles of the DTI Law have been in force since mid-2025. The PDPL and Decree 356 took effect on 1 January 2026. The AI Law followed on 1 March 2026, with Decree 142 entering force on 1 May 2026. Decree 100/2026/ND-CP on intellectual property was issued in April 2026.
For AI systems already in operation before 1 March 2026, Decree 142 allows a transition period. Providers must submit a notice and transition plan to the Ministry of Science and Technology's one-stop portal within 60 days of the decree's effective date, in other words by the end of June 2026. That window gives companies a short period to classify existing systems, prepare conformity assessments, and adjust labeling and incident-reporting workflows.
Some implementing instruments are still pending. The Ministry of Public Security is preparing a decree on administrative sanctions for cybersecurity and personal-data violations, which will give enforcement agencies the detailed penalty scales needed to apply the PDPL's headline fines. Until that decree is issued, enforcement is likely to rely on warnings and corrective orders rather than revenue-based penalties. That does not mean companies should delay preparation; the 60-day AI transition deadline and the PDPL's existing notification obligations are already live.
The overlap between laws also creates interpretive gaps. The DTI Law and the AI Law both touch on high-risk AI systems. The PDPL and the Data Law both govern digital data. The IP Law, as amended, and Decree 100 both address AI-generated works. Regulators will need to issue further circulars to clarify which agency takes the lead when rules collide. Investors should expect a period of regulatory calibration before enforcement becomes fully predictable.
How Companies Are Responding
Multinationals with Vietnamese operations are conducting data-mapping exercises to identify where personal data is collected, stored, and transferred. Many are localising backups that were previously held only in regional hubs, separating consent mechanisms from general terms of service, and documenting the legal basis for each cross-border flow. These steps are labour-intensive but necessary both for compliance and for due diligence in any future transaction.
Domestic technology firms are applying for recognition under the DTI Law's incentive schemes. Software houses, chip-design startups, and AI data-centre developers are registering for concentrated digital-technology zones and preparing dossiers for special investment incentives. The zones offer a cluster model: shared infrastructure, proximity to universities, and streamlined administrative procedures.
Law firms and consultancies are building PDPL and AI compliance practices. The demand is not limited to large enterprises; small and medium-sized companies that process customer data or deploy chatbots now need risk classifications, data-processing agreements, and breach-response plans. That service market is likely to grow faster than the underlying tech market in the near term.
The Investment Angle
The framework creates a classic dual-track opportunity. On one side, compliance costs will rise for any company handling Vietnamese data or deploying AI. On the other side, the DTI Law's incentives and the National AI Development Fund direct capital toward favoured sectors. Investors who can underwrite both sides—backing the infrastructure providers and the compliance enablers—are likely to find the risk-adjusted returns most attractive.
The safest early bets are probably not the most speculative AI models. They are the regulated utilities of the digital economy: data centres with clear localisation plans, cybersecurity and compliance services, semiconductor packaging and testing facilities, and enterprise software that helps Vietnamese companies meet their new obligations. These businesses benefit from the same regulatory tailwind without carrying the same product-classification risk as consumer-facing AI applications.
