BSA recommends rationalizing the Data Security Law with Vietnam's existing data governance framework, adopting a narrower and risk-based approach to data classification and cross-border data transfers, removing overlapping AI-related obligations, harmonizing incident reporting requirements with international best practices, and ensuring financial penalties are proportionate and based on revenue within Vietnam.
Comprehensive privacy legislation must create strong obligations for all companies that handle consumer data. These obligations will only be strong enough to protect consumer privacy and instill trust, though, if they reflect how a company interacts with consumer data.