🇻🇳Vietnam — APAC AI Regulation

Vietnam AI & Data Compliance

Navigate Vietnam's Decree 13/2023 personal data protection requirements, Cybersecurity Law obligations, and State Bank AI governance guidance — with automated compliance built for the Vietnamese regulatory environment.

Regulatory Landscape

Key Vietnam Regulations

The primary laws and regulations governing AI systems and data processing in Vietnam.

Decree 13/2023/ND-CP

Personal Data Protection Decree

In Force

Vietnam's primary personal data protection law, effective July 2023. Establishes data subject rights, controller/processor obligations, cross-border transfer rules, and mandatory data protection impact assessments for sensitive data processing.

Law on Cybersecurity (2018)

Cybersecurity Law

In Force

Requires data localisation for certain categories of data, cybersecurity assessments for critical information infrastructure, and incident reporting obligations for technology service providers.

AI Strategy 2021–2030

National AI Strategy

Active

Vietnam's national strategy for AI development, setting out governance principles, ethical AI guidelines, and a roadmap for AI regulation across key sectors including finance, healthcare, and public services.

Circular 09/2020/TT-NHNN

State Bank of Vietnam — Fintech & AI Guidance

In Force

Guidance from the State Bank of Vietnam on technology risk management and AI use in financial services, including model risk, algorithmic decision-making, and cybersecurity requirements.

Compliance Obligations

What Organisations Must Do

Data Protection Impact Assessments (DPIA) for AI systems processing sensitive personal data
Consent management and data subject rights fulfilment for AI-driven processing
Data localisation compliance for AI systems handling Vietnamese citizen data
Cybersecurity assessments for AI systems in critical information infrastructure
Model risk management and algorithmic transparency for financial AI systems
Incident reporting and breach notification within prescribed timeframes
Third-party AI vendor due diligence and contractual safeguards
Board-level accountability for AI governance and data protection

How DotCoAi Helps

Built for Vietnam Compliance

Decree 13 Compliance Assessment

Gap analysis of your AI systems against Decree 13/2023 obligations — data mapping, DPIA workflows, and consent management aligned to Vietnamese requirements.

Data Localisation & Transfer Controls

Assessment and implementation of data localisation controls for AI systems processing Vietnamese personal data, including cross-border transfer safeguards.

AI Governance Policy Development

Vietnam-specific AI governance policies, model risk frameworks, and algorithmic accountability documentation aligned to national AI strategy principles.

Incident Response & Breach Notification

Automated monitoring and structured incident response workflows to meet Vietnam's cybersecurity incident reporting obligations.

Regulatory Monitoring

Continuous monitoring of Vietnam's evolving AI and data protection regulatory landscape — alerts and impact assessments as new rules emerge.

Financial Services AI Compliance

Specialist support for State Bank of Vietnam technology risk and AI requirements — model validation, algorithmic transparency, and examination readiness.

Get Started

Ready for Vietnam compliance?

Talk to our APAC regulatory specialists about your Vietnam AI and data protection obligations.

Book a Consultation

Speak directly with a senior AI governance specialist. We'll understand your needs and map out the right engagement for your organisation.

Response within 24 hoursBook Now

All APAC Regulations

Take our AI Readiness Assessment to benchmark your governance maturity, identify gaps, and get a personalised report — completely free.

Takes ~10 minutesStart Free