![]() |
| An officer of the Department of Cybersecurity and Hi-tech Crime Prevention, the Ministry of Public Security, monitors malware trend charts in cyberspace__Photo: VNA |
Foreign online service providers that fail to comply with Vietnam’s cybersecurity and data storage requirements may face access restrictions under Government Decree 327/2026/ND-CP, which guides in detail the implementation of Article 14 of the Law on Cybersecurity.
Under the decree, there are seven circumstances in which access from Vietnam may be blocked for cross-border information systems.
Specifically, access will be restricted in case the operator of an overseas-based information system fails to comply with a request for removal of unlawful information or fails to provide data in support of investigation conducted by the Vietnamese specialised cybersecurity protection force.
Restrictions may also be imposed on information systems showing signs of distributing malware, taking control of devices, or conducting cyberattacks or cyberterrorism from outside Vietnam in a manner that affects national infrastructure.
Also subject to restrictions are information systems that repeat violations though having been handled for providing, sharing or disseminating unlawful content in cyberspace, thus affecting national security or social order and safety; or system operators that fail to comply with requests from the specialised cybersecurity protection force to block, remove or delete unlawful information within the country.
Access restrictions will likewise be applied to cross-border platforms that provide, share or disseminate content opposing the State of the Socialist Republic of Vietnam, inciting riots, or disrupting public order.
Other cases of restrictions include information systems whose operators fail to implement control measures or remedy technical incidents after the systems are exploited for cyber espionage, cyberterrorism, unauthorised intrusion or attacks that cause damage to information systems of critical importance to national security; and overseas-based information systems that process personal data of Vietnamese citizens in violation of Vietnam’s law while the system operators fail to abide by administrative sanctioning decisions of the specialised cybersecurity protection force or other competent authorities.
Foreign enterprises providing telecommunications, Internet or other added services in cyberspace in Vietnam may also be blocked if they fail to establish a branch or representative office in the country as required by law, or fail to comply with data storage obligations under Vietnam’s law.
The decree also specifies cases subject to suspension of transactions involving payment accounts, e-wallets and digital accounts.
Accordingly, transactions may be suspended in case a payment account, an e-wallet or a payment instrument is identified as being used to receive, disburse or transfer funds earned from unlawful activities; or in case an account holder uses false information or forged documents, or rents, borrows, or otherwise uses another person’s account to conduct suspicious transactions in cyberspace.
Other circumstances include the use of digital accounts for unlawful purchase, sale, trading or conversion of foreign currencies or digital assets; the use of cyberspace to interfere with transactions or alter recipient account information for fraudulent purposes or the misappropriation of assets; and the use of cyberspace to fraudulently raise capital or appropriate assets.
Digital accounts found to have been opened in violation of statutory procedures or maintained using falsified identification information may also be suspended.
In addition, suspension may be applied to a service provider that fails to suspend transactions or freeze a digital account after an error, a mistake or information leakage is detected, or after the specialised cybersecurity protection force so requests.
Notably, service providers and information system operators are required to provide information and data at the request of the specialised cybersecurity protection force or other competent authorities within 24 hours for ordinary requests or within three hours in emergency situations.- (VLLF)
