It is a significant challenge for businesses providing cross-border services in Vietnam when the provisions of the Law on Cyber Security 2025 take effect

Insights
It is a significant challenge for businesses providing cross-border services in Vietnam when the provisions of the Law on Cyber Security 2025 take effect
Posted on: 25/03/2026

    The strong development of the digital economy has gradually blurred geographical boundaries in the provision of services in cyberspace. Technology businesses such as Google, Meta, Netflix,... can reach millions of users in Vietnam without a physical presence, thereby forming an increasingly popular and difficult to control cross-border service delivery model. This invisibly entails many risks in terms of security and confidentiality of user data. Therefore, ensuring cyber security and information management is increasingly required, requiring coordination between businesses and professional management agencies against potential risks, directly harming the State and individuals and organizations using cross-border products and services.

     

    Ensuring cyber security and information management is increasingly required.

     

    1. Requirements for conditions for provision of cross-border services of foreign enterprises in Vietnam

    Clause 3, Article 25 of the Law on Cyber Security (ANM Law) 2025 requires foreign enterprises providing services on the Internet or additional services in cyberspace in Vietnam (also known as enterprises providing cross-border services in Vietnam) to set up a branch or representative office in Vietnam. However, not all cases are mandatory to set up branches and representative offices in Vietnam.

    Accordingly, foreign enterprises must only establish branches and representative offices when required by specialized agencies and fully meet the following factors: (i) business activities in certain fields[1]; (ii) the services provided are used to commit the infringement; (iii) There has been a written request for coordination, prevention, investigation and handling after 03 times within a maximum period of 6 months but the enterprise has no remedial solutions or other activities that invalidate the cyber security protection measures. In some force majeure cases leading to non-compliance, the foreign enterprise must notify within 03 working days and find a remedial plan within 30 working days. Therefore, in case there is a decision on the establishment of the Minister of Public Security, the enterprise must comply with the establishment of a branch or representative office within 12 months from the date of the decision to take responsibility for the risks of sanctioning.

    In addition, to ensure that the provision of services complies with the new regulations, enterprises need to review whether the cybersecurity services they provide are entitled to provide according to the provisions of Clause 2, Article 28 of the Law on ANM 2025. In addition, the business of cyber security services must also ensure technical regulations on the basis of documents developed by the Ministry of Public Security and the law on standards and technical regulations.

    2. Cyber information security and data security are Vietnam's priorities

    One of the top cyber security protection activities set out for Vietnam today is the assurance of two important factors:[2] cyber information security and data security. These requirements apply not only to domestic enterprises but also to enterprises providing cross-border services in Vietnam. This aims to prevent acts that sabotage or threaten national security and social order such as unauthorized access, use, disclosure or modification of information or data in cyberspace.

    For cyber information security activities, enterprises are required to implement activities such as:[3] (i) authenticating and protecting information and accounts of service users; (ii) providing information for the protection of cyber information security; (iii) prevent and handle infringing information and application services; (iv) suspension or discontinuation of the provision of services; (v) storing and managing system logs.

    In case there is a request for coordination from specialized agencies, enterprises need to promptly provide information shared and posted in cyberspace, especially information that is anti-State. For example, when there are signs of a violation in cyberspace, this organization must authenticate user information, secure it and provide it to the specialized authority within 24 hours from the time of the request[4]. Except for some emergency cases[5], the deadline is 03 hours at the latest. At the same time, measures to prevent, restrict, delete information or suspend the provision of services will be enclosed.

    In terms of data security, this issue is not only regulated by the Law on ANM but also within the scope of the relevant laws on data and personal data. Within the scope of the ANM Law, the new regulation focuses on technical, organizational and mechanism measures to ensure the safety of data appearing in cyberspace. For example, for the type of critical data, the processing information system must meet the minimum security requirements in the level 3 information system and apply a 24/7 monitoring mechanism.[6] Notably, businesses providing cross-border services in Vietnam are required to carry out data transfer assessments when these subjects often have to process data on their platforms.[7]

     

    When detecting violations in cyberspace, IP address identification is considered one of the important ways to serve the investigation and verification of cyber security protection forces.

     

    3. Strengthen strict control of content related to Artificial Intelligence

    In cyberspace, potential risks arising from Artificial Intelligence (AI) are a significant challenge for providers of cybersecurity products and services. The ANM Law has initially made additions to regulations in response to the continuous development of this technology. Accordingly, the Law strictly prohibits the use of artificial intelligence to fake other people's videos, images, and voices for illegal purposes.[8] The introduction of this provision into law for the first time shows the timely adjustment of the law to the reality that cyberspace is increasingly being used to defraud and infringe on privacy.

    However, in the face of the rapid development and increasingly far-reaching impact of AI, legal issues related to this technology require a more comprehensive and specialized regulatory framework. Therefore, detailed regulations on AI development, deployment and management will be regulated in detail in an independent legal document, namely the Law on Artificial Intelligence 2025 which took effect on March 1, 2026.

    4. Coordinating with state agencies in identifying IP addresses

    When detecting violations in cyberspace, IP address identification is considered one of the important ways to serve the investigation and verification of cyber security protection forces. According to the provisions of the Law on Security, telecommunications and internet service providers must be responsible for identifying IP addresses so that cyber security protection forces can take appropriate cyber security protection measures. A number of IP address identification principles are also set for businesses such as:[9] (i) IP address identification management must ensure accuracy and unique traceability to service users, (ii) maintain a technical system to record and store for identification; (ii) must carry out the identification throughout to serve the requirements of state management. These steps are expected to support the state management of cybersecurity, ensuring the safety of users in cyberspace.

    However, this incurs a certain compliance cost for businesses when businesses have to ensure strong security protection funds. For example, businesses may have to invest more in technical infrastructure and professional personnel to implement activities to record, store and manage IP address data. For platforms with a large number of users or cross-border operations, meeting these requirements can significantly increase operating costs.

    To reduce the burden of compliance costs and initial risks, businesses can consider strengthening cooperation with specialized technology service providers to share costs and resources in implementing cybersecurity measures. In the next stages, businesses can consider optimizing the available technology infrastructure, applying data storage and management solutions based on the experience from the previous technology service unit. At the same time, businesses must have an experienced legal team that regularly updates and coordinates with professional parties to promptly comply with new requirements that arise.

    Overall, the ANM Law 2025 is expected to create significant changes in the compliance obligations of businesses operating in cyberspace in Vietnam. Especially foreign businesses providing cross-border services. The new regulations force these enterprises to proactively assess the impact of these regulations on their business activities, and at the same time prepare appropriate budgets and necessary technical and legal measures to avoid disruptions and maintain stability in the process of providing services in Vietnam.

    Lawyer Nguyen Van Phuc - Le Viet Hung

    HM&P Law Firm

     

    Read more: Thách thức không nhỏ cho các doanh nghiệp cung cấp dịch vụ xuyên biên giới tại Việt Nam khi các quy định Luật An ninh mạng 2025 có hiệu lực


    [1] Point a, Clause 3, Article 28 of the Draft Decree detailing a number of articles of the Law on Cyber Security.

    [2] Articles 25 and 26 of the Law on ANM 2025; Chapters IV and V of the Draft Decree detailing a number of articles of the Law on Cyber Security.

    [3] Article 25 of the Draft Decree details a number of articles of the Law on Cyber Security.

    [4] Points a, b, Clause 2, Article 25 of the Law on ANM 2025.

    [5] Point a, Clause 2, Article 25 of the Law on ANM 2025.

    [6] Points a, b, Article 31 of the Draft Decree detailing a number of articles of the Law on Cyber Security.

    [7] Point e, Clause 2, Article 26 of the Law on ANM 2025.

    [8] Point g, Clause 2, Article 7 of the Law on ANM 2025.

    [9] Article 38 of the Draft Decree detailing a number of articles of the Law on Cyber Security.