Notably, the Law adds regulations related to user identification, data storage, artificial intelligence (AI), Deepfake, and the responsibilities of businesses when requested by specialized agencies.
Cybersecurity Law 2025: New Points Businesses Need to Note
The Cybersecurity Law 2025 officially takes effect on July 1, 2026, marking many significant changes in cybersecurity management, user data, and service provision activities in Vietnam's cyberspace.
Notably, the Law adds regulations related to user identification, data storage, artificial intelligence (AI), Deepfake, and the responsibilities of businesses when requested by specialized agencies.
1. Unified State Management of Cybersecurity
One of the notable changes in the Cybersecurity Law 2025 is the consolidation and unification of previous regulations on network information security and cybersecurity.
Accordingly, the Government uniformly implements state management of cybersecurity, and the Ministry of Public Security is the focal agency assisting the Government in performing this task.
The unification of management aims to limit overlaps between previous regulations and create a legal basis for addressing new issues arising in the digital environment.
2. Increased Responsibility for User Authentication and Identification
Businesses providing services on telecommunications networks, the Internet, and other cyberspace services must enhance their ability to identify user information.
Some notable obligations include:
-
Identifying the IP addresses of organizations and individuals using Internet services;
-
Authenticating information when users register digital accounts;
-
Providing user information to specialized forces upon request;
-
Storing system logs to serve verification, investigation, and handling of violations.
According to the Law, the normal time limit for providing information can be up to 24 hours from the receipt of the request. In urgent cases related to national security or human life, the time can be reduced to 03 hours.
3. Additional Mechanism for Removing Violating Applications and Services
Not only limited to requiring the removal of violating content, the Cybersecurity Law 2025 also adds the ability to request:
For requests to block or remove violating information, businesses must comply within the prescribed time limit. In urgent cases threatening national security, the processing time can be reduced to 06 hours.
4. Regulations on AI and Deepfake
The rapid development of artificial intelligence makes it increasingly difficult to control acts of impersonating images, videos, and voices.
The Cybersecurity Law 2025 adds a regulation prohibiting the use of AI or new technologies to impersonate others' videos, images, or voices contrary to legal regulations.
In addition to Deepfake, some other acts also mentioned include:
-
Impersonating or faking information, images;
-
Mimicking products, trademarks, or brands using technology;
-
Using technology to affect the reputation of organizations or businesses.
This regulation creates an additional legal basis for handling forms of fraud and technological impersonation in the online environment.
5. Data Storage and Protection Requirements
The Law continues to impose requirements on businesses that collect, exploit, or analyze user data in Vietnam.
Data within the scope of regulation may include:
Businesses falling under the scope of application must store data in Vietnam for a period specified by the Government.
For foreign businesses subject to regulation, the Law also requires the establishment of a branch or representative office in Vietnam.
6. Enhanced Protection of Children in Cyberspace
The Cybersecurity Law 2025 expands the protection mechanism for vulnerable groups, including children, the elderly, and individuals with cognitive difficulties.
Service providers must implement measures to control, prevent, and remove information that may be harmful to children.
Parents or guardians also have the responsibility to manage and supervise their children's use of online accounts and services.
7. What Do Businesses Need to Prepare?
Given the new requirements, businesses should proactively review their systems and operating procedures, especially activities related to personal and user data.
Some priority tasks include:
-
Reviewing and classifying information systems;
-
Checking the ability to identify and store IP addresses;
-
Evaluating data storage procedures in Vietnam;
-
Developing rapid response procedures to meet requests within 3 hours, 6 hours, or 24 hours;
-
Updating security policies and system usage regulations;
-
Training employees on data security, online fraud, and AI risks.
For state agencies, organizations, and businesses, it is important to note the requirement to allocate at least 15% of the total annual budget for digital transformation and information technology application programs and projects to cybersecurity protection activities.
Conclusion
The Cybersecurity Law 2025 imposes many new requirements on businesses operating in the digital environment, especially concerning data management, user identification, AI, and the responsibility to handle violating information.
Businesses need to proactively review their technical infrastructure, data management processes, and internal policies to prepare for compliance with the Law's provisions from July 1, 2026.