Alongside the rapid growth of the information technology sector, adopting and deploying cloud computing solutions has become a key part of the business strategy for many companies in Vietnam. However, this growth has come with tighter legal compliance requirements around securing and deploying cloud infrastructure.
In Vietnam, several important regulations have been issued in legal documents, including the 2013 Constitution and the Law on Network Information Security, the Law on Cybersecurity, the Civil Code, and the Telecommunications Law, all focused on protecting personal data and ensuring information security online.
Complying with Vietnam's cloud computing laws and regulations is not only essential for protecting personal information and sensitive business data — it also determines how far customers and partners will trust a cloud provider enough to use its services. Organizations and individuals need a firm grasp of the legal requirements and must apply them correctly, so that their use of cloud computing is responsible and compliant with local law.
Personal information security rules
As personal data is increasingly stored and published in digital environments, ensuring information security for users has become an urgent issue. Accordingly,Hiến pháp năm 2013enshrined the right to protection of information and personal privacy. Subsequently, inthe Civil Code 2015andLaw on Network Information Security 2015 (Luật An toàn Thông tin mạng 2015)set out the fundamental principles for protecting data privacy, governing the collection, use, modification and deletion of personal information, and also established the Government’s responsibility to protect citizens’ private data.
The 2015 Code sets out the obligations of organizations and individuals in processing information, requiring them to keep information secure and to publish their policy on how that data is used. Next,Cybersecurity Law 2018 (Luật An ninh mạng năm 2018)added a requirement that companies providing online services in Vietnam must notify users directly if their data is breached, damaged or lost. Vietnamese law also prescribes specific measures for dealing with conduct that violates personal data, such as the offence of “illegally providing or using information on computer or telecommunications networks” under the Penal Code 2015 (Bộ luật Hình sự 2015).
In 2022, the Vietnamese government issuedDecree No. 53/2022/ND-CPguiding the implementation of a number of articles of the Cybersecurity Law 2018. This decree is regarded as an important step in strengthening cybersecurity protection and governing activity in cyberspace in Vietnam. It sets out specific guidance on the Cybersecurity Law, including the rights and obligations of the organizations, individuals and entities involved in cybersecurity activity. The decree also prescribes specific measures for maintaining cybersecurity in areas such as network infrastructure management, protection of critical information, prevention of cyberattacks, and enforcement against cybersecurity violations.
And most recently,Decree 13/2023/ND-CPon personal data protection was issued to advance the exercise of the associated rights and obligations. The decree gives specific, clear direction to organizations and individuals that collect, process, store and manage personal data. In particular, it requires the purpose of processing to be clearly demonstrated, sets limits on data retention periods, and establishes an obligation to report personal data processing to the competent authority. Decree 13 also states that organizations must apply appropriate security measures to keep personal information safe.
Intellectual Property regulations
Vietnam has issued a range of legal instruments — laws, decrees and circulars — to regulate and protect intellectual property rights comprehensively. Some of the key instruments areIntellectual Property Law 2009 (Luật Sở hữu Trí tuệ năm 2009)(as amended and supplemented in 2019),Decree No. 99/2013/NĐ-CPon administrative penalties in the field of industrial property, andDecree No. 28/2017/NĐ-CPamending and supplementingDecree No. 131/2013/NĐ-CPon administrative penalties relating to copyright and related rights.
Beyond domestic law, Vietnam also observes its international commitments on intellectual property protection. The multilateral and bilateral agreements to which Vietnam is a party play an important role in promoting effective copyright protection — among them the TRIPS Agreement and intellectual property agreements with international partners such as the United States and Switzerland.
Legal framework for cloud computing
On 3/4/2020, Vietnam's Ministry of Information and Communications issuedOfficial Dispatch No. 1145/BTTTT-CATTTto provide guidance on a set of technical standards and specifications (the “Guidelines”) for cloud computing solutions used in e-government deployments.
State agencies and organizations will rely on these Guidelines to evaluate and select cloud computing solutions or services for e-government development. Private businesses are also encouraged to consult these Guidelines when setting up and deploying their own cloud computing platform solutions.
This is the first time Vietnam has published a set of criteria and technical specifications specifically for cloud platforms. The aim is to help domestic IT companies develop core technologies themselves and reduce dependence on foreign technology. It also supports building cloud platforms for e-government at national and local level, and advancing the digital government, digital economy and digital society.
The set of technical standards and specifications falls into two groups. Group 1 covers standards, specifications and features relating to: (1) virtual machines, (2) storage devices, (3) networking and software-defined networking, (4) physical machines, (5) administration and operations, and (6) integration and other related requirements. Group 2 covers requirements relating to: (1) baseline information security functionality, and (2) security configuration for cloud computing infrastructure.
The Guidelines also define cloud computing (its definition and essential characteristics), classify cloud deployment models (public, private, hybrid and multi-purpose cloud), and classify cloud service models: IaaS (Infrastructure as a Service), PaaS (Platform as a Service) and SaaS (Software as a Service). The Guidelines set out two options for deploying a cloud platform: self-deployment, self-administration and self-operation; or the use of professional cloud computing services from cloud providers.
The self-deployment, self-administration and self-operation option requires state agencies and enterprises to have an experienced team capable of building, administering and maintaining the infrastructure and securing it themselves. They are therefore advised to take option 2: using cloud computing services from professional providers. For that option, the Ministry of Information and Communications recommends that state agencies and enterprises give preference to cloud providers that meet the prescribed technical standards and specifications and that appear on the list published by the Ministry. The selected cloud providers must comply with the laws on cyberinformation security, comply with the prescribed technical standards, and meet the technical standards and specifications set out in the Guidelines.
Recently, in discussions related toDraft Telecommunications Law (amended), views have been put forward calling for a clearer and more flexible legal framework to govern and oversee cloud computing and data center activity. The aim is both to encourage the development and adoption of the technology in improving how organizations and businesses operate, and to protect information security and user privacy.
Specific provisions in the Law on Telecommunications will accordingly be adjusted to align with requirements for information security, data governance and privacy in cloud computing and data center environments. Businesses have also asked for simpler registration procedures and business conditions in telecommunications, data centers and cloud computing, to make operating easier. This reflects the government's attention to the sector and its willingness to create the conditions for innovation and growth in information technology in Vietnam.
Pho Tue SoftWare Solutions JSC's solutions are designed to comply with Vietnamese law
For businesses, choosing the right cloud provider and ensuring full compliance with Vietnamese law is the most effective foundation for digital transformation. With two data centers in Vietnam, Pho Tue SoftWare Solutions JSC maintains strict safety and security practices, certified against international standards including ISO 27001, ISO 27017, ISO 27019 and PCI DSS, and complies with Vietnamese legal requirements on cybersecurity and cloud computing.
Pho Tue SoftWare Solutions JSC has also met all of the criteria issued by the Ministry of Information and Communications in 2020 for assessing “Make in Vietnam” cloud platforms — 153 criteria in total, comprising 84 technical criteria and 69 information security criteria. This reflects our firm commitment to protecting intellectual property and personal data security in cloud computing.