Data, Privacy & Cybersecurity

Data, Privacy & Cybersecurity

It is a significant challenge for businesses providing cross-border services in Vietnam when the provisions of the Law on Cyber Security 2025 take effect

The strong development of the digital economy has gradually blurred geographical boundaries in the provision of services in cyberspace. Technology businesses such as Google, Meta, Netflix,... can reach millions of users in Vietnam without a physical presence, thereby forming an increasingly popular and difficult to control cross-border service delivery model. This invisibly entails many risks in terms of security and confidentiality of user data. Therefore, ensuring cyber security and information management is increasingly required, requiring coordination between businesses and professional management agencies against potential risks, directly harming the State and individuals and organizations using cross-border products and services.

Develop an internal AI use policy: Don't rush to make it available

The Law on Artificial Intelligence ("AI") 2026 officially takes effect on 01 March, 2026, this specialized law means that the use of AI in businesses is a matter of risk management, responsibility and compliance. Meanwhile, many businesses are sprinting to build policies to use AI internally as a way to respond to the situation. The common reaction of many businesses in using AI today is divided into two extremes. On the one hand, it is floating, allowing personnel to freely use AI tools without direction, without controlling input data, without delineating responsibilities. The other side is frozen, concerned about risks, so they prohibit and tighten to the point of suppressing the benefits that AI can bring. Neither is a sustainable strategy.

What businesses need to do when the Law on Artificial Intelligence 2025 has taken effect from 01 March 2026

As of March 1, 2026, the Law on Artificial Intelligence 2025 ("Law on AI") has officially come into effect, marking a transformation when it is officially recognized separately in specialized legal regulations. Currently, the Government is also urgently collecting comments on 04 draft documents, including: (i) Decree guiding the implementation of the Law on AI; (ii) Circular guiding the National Artificial Intelligence Ethics Framework; (iii) 02 Decisions related to the List of high-risk artificial intelligence systems and the List of datasets for the development of artificial intelligence in essential fields to soon complete this very new legal framework in Vietnam.

As AI becomes a driving force and tool for global M&A

The rise of generative AI in recent years is not merely a technological trend but has become a core catalyst to reshape the growth strategy of businesses. The global M&A market is on track to recover strongly with the total transaction value in the first nine months of 2025 reaching $1.93 trillion, up 10% year-on-year . In particular, AI plays the role of the "heart" of megadeals (over $5 billion) and is a vital factor that forces old competitors to shake hands to survive.

How does Vietnam regulate the protection of student data in schools?

Schools around the world as well as in Vietnam are using more and more technology in teaching and learning. Creating conditions for educational technology (EdTech) companies to take advantage of and fully exploit the "data gold mine" of students. This forces countries, including Vietnam, to take action to strictly protect student data in an increasingly digital educational environment.

Patient privacy should be a priority for the hospital

According to the Law on Personal Data Protection 2025 (Law on PDP), medical data is classified as sensitive personal data "associated with the privacy of individuals, when infringed upon, will directly affect legitimate rights and interests". This reflects the importance of protecting health records, personal information of patients. In a healthcare setting, patient trust in information confidentiality is crucial. If patients suspect that their information has been disclosed or used unauthorized, they may lose trust, not cooperate fully with treatment, or be afraid to honestly declare sensitive matters.

Q&A on DPO in Vietnam: Practical challenges in the appointment process

In the context of the Law on Personal Data Protection 2025, which has formally established the legal framework for the appointment and operation of Data Protection Officers (DPOs), practical implementation in Vietnam continues to raise a number of complex issues. These include the DPO’s right to cease performing assigned duties, the choice between an internal and outsourced DPO model, questions of legal liability, and mechanisms to ensure functional independence. The Q&A section below addresses common challenges arising during the appointment process and provides structured legal and governance perspectives on managing the DPO role in Vietnam.

Pharmaceutical businesses need to comprehensively review their data policies

For the pharmaceutical industry, specifically for today's pharmacy chains, the stored data block is not just a type of transaction information between drug sellers and drug buyers, but also health data - a sensitive form of data under the new law and is required to be more strictly protected. However, there are gaps in the way pharmacies collect and separate their data management that can expose these businesses to legal risks even as they strive to demonstrate compliance with current laws.

Data Protection Day 2026: A reminder of the importance of data protection in the digital era

In the era of deepening digitalization, personal data has become a valuable but also vulnerable asset. January 28 is chosen annually to celebrate Data Protection Day, a global event aimed at raising awareness of privacy and protecting personal information. In 2026, with the theme of emphasizing "Own Your Privacy", the issue of protecting and mastering each individual's data has become more urgent than ever, especially when AI and cloud technology are developing strongly. The article will provide some information about the origin and meaning of this day in contemporary history, and at the same time set in the context of modern Vietnam – a country that is transforming strongly in the digital economy but is also facing many challenges in protecting the privacy of each individual.

Use of biometric data in medical examination and treatment - Need the highest level of security

Vietnam's health sector has implemented digitalization in the management and operation of electronic medical records, online health insurance payments, patient identification with chip-based citizen identification cards, and even the application of AI in diagnosing and monitoring patient health. This leads to medical examination and treatment facilities ("hospitals") collecting and processing more and more personal data of patients. However, compliance with data security and privacy in this field in Vietnam has not been given proper attention.

Don't play with user biometric data

Unlike passwords or bank card numbers that can be changed, biometric data is permanently tied to the human body. Once illegally collected, used, or leaked, individuals have almost no ability to "recall" or "reset" their biological characteristics. Therefore, many legal systems around the world have considered biometric data as sensitive personal data and set strict protection requirements.

Hospitals face significant challenges in protecting patient data

Vietnam's health sector, especially hospitals, will face many difficulties in complying with the new provisions of the Law on Personal Data Protection 2025 (the Law on PDP) which takes effect from January 1, 2026. This confusion stems not only from the shift from traditional management systems to digitalized models, where data is easily exposed, leaked, or abused, but also from the important nature of the type of data that hospitals are collecting and holding.