Curtailing Free Expression, Opinion and Information Online in Southeast Asia which provide online banking services.491 Article 26 provides that companies must “set up mechanisms to authenticate information when users register digital accounts”, “delete or prevent” any information published on their networks or information systems deemed in violation of the law “within 24 hours”, and “cease to provide services on the telecommunication works or the internet” to any person who posts such alleged illegal content.492 The law further dictates that companies must provide data on their users “when required” to MPS’ “specialized force in charge of cybersecurity protection” or “competent authorities” under the MIC – in violation of the users’ right to privacy – and “implement requirements from the competent authorities in investigating and sanctioning violations”, regardless of whether such requirements may infringe on human rights such as freedom of expression and information.493 The law also permits the MPS to conduct “cybersecurity audits” to monitor compliance.494 The LOCS is also problematic because it compels data localization – requiring companies to “store in Vietnam the personal information of the service users in Vietnam and important data related to national security” and “locate their head offices or representative offices in Vietnam”, where the “(g)overnment shall detail what types of information shall be stored in Vietnam and which enterprises are required to locate their head offices or representative offices in Vietnam”.495 These requirements are vague and do not guarantee that confidential personal information belonging to users will not be provided in violation of their rights to privacy and security, and are left open to the unfettered discretion of State authorities.496 Asia Internet Coalition, a coalition representing internet companies on matters of public policy, further highlighted that data localization would not ensure data confidentiality, as proposed by policy makers and in fact “potentially create a focal target for cyber-attacks and consequently make Vietnam more vulnerable in terms of cyber security”.497 491 Law on Cybersecurity, article 26(2); See also Duane Morris, ‘Vietnam’s new Cybersecurity Law: A headache in the making?’, July 2018 (‘Duane Morris, July 2018’), Available at: https://www. duanemorris.com/articles/static/cooper_le_cybersecurity_practitioner_0718.pdf 492 Law on Cybersecurity, articles 26(2)(a), (b) and (c). 493 Law on Cybersecurity, articles 26(2)(a), (b), (c), (dd). 494 Law on Cybersecurity, articles 12, 24. 495 Law on Cybersecurity, articles 26(2)(d), 26(3). 496 Duane Morris, July 2018. 497 “In most instances, data localization mandates do not increase commercial privacy nor data security.Therefore, it is important to recognize that the confidentiality of data does not generally depend on which country the information is stored in, only on the measures used to store it securely. Data security depends on the technical, physical, and administrative controls implemented, regardless of where the data is stored.” See AIC, 13 December 2018, p6. 129

Select target paragraph3