Curtailing Free Expression, Opinion and Information Online in Southeast Asia
which provide online banking services.491 Article 26 provides that companies
must “set up mechanisms to authenticate information when users register
digital accounts”, “delete or prevent” any information published on their
networks or information systems deemed in violation of the law “within 24
hours”, and “cease to provide services on the telecommunication works or
the internet” to any person who posts such alleged illegal content.492 The
law further dictates that companies must provide data on their users “when
required” to MPS’ “specialized force in charge of cybersecurity protection”
or “competent authorities” under the MIC – in violation of the users’ right
to privacy – and “implement requirements from the competent authorities
in investigating and sanctioning violations”, regardless of whether such
requirements may infringe on human rights such as freedom of expression
and information.493 The law also permits the MPS to conduct “cybersecurity
audits” to monitor compliance.494
The LOCS is also problematic because it compels data localization
– requiring companies to “store in Vietnam the personal information of the
service users in Vietnam and important data related to national security”
and “locate their head offices or representative offices in Vietnam”, where
the “(g)overnment shall detail what types of information shall be stored
in Vietnam and which enterprises are required to locate their head offices
or representative offices in Vietnam”.495 These requirements are vague
and do not guarantee that confidential personal information belonging to
users will not be provided in violation of their rights to privacy and security,
and are left open to the unfettered discretion of State authorities.496 Asia
Internet Coalition, a coalition representing internet companies on matters
of public policy, further highlighted that data localization would not ensure
data confidentiality, as proposed by policy makers and in fact “potentially
create a focal target for cyber-attacks and consequently make Vietnam more
vulnerable in terms of cyber security”.497
491 Law on Cybersecurity, article 26(2); See also Duane Morris, ‘Vietnam’s new Cybersecurity Law:
A headache in the making?’, July 2018 (‘Duane Morris, July 2018’), Available at: https://www.
duanemorris.com/articles/static/cooper_le_cybersecurity_practitioner_0718.pdf
492 Law on Cybersecurity, articles 26(2)(a), (b) and (c).
493 Law on Cybersecurity, articles 26(2)(a), (b), (c), (dd).
494 Law on Cybersecurity, articles 12, 24.
495 Law on Cybersecurity, articles 26(2)(d), 26(3).
496 Duane Morris, July 2018.
497 “In most instances, data localization mandates do not increase commercial privacy nor
data security.Therefore, it is important to recognize that the confidentiality of data does not
generally depend on which country the information is stored in, only on the measures used to
store it securely. Data security depends on the technical, physical, and administrative controls
implemented, regardless of where the data is stored.” See AIC, 13 December 2018, p6.
129