Vietnam and Nigeria Tighten the Enforcement Clock on Data Flows

Regulators in Vietnam and Nigeria are tightening cross-border data and profiling enforcement, raising the bar for approvals, filings, and audit evidence.

Updated

What is this trend?

Vietnam and Nigeria are turning cross-border data rules into active enforcement, forcing companies to secure approvals, filings, and proof of lawful processing before data moves.

  • Vietnam may ban some core-data exports and require prior approval for sensitive transfers.
  • Cross-border transfer filings now have tight deadlines, with suspension risk for violations.
  • Nigeria is targeting unlawful profiling and behavioral ads with proof-of-compliance deadlines.
  • Compliance teams need transfer maps, contracts, logs, and evidence across cloud and AI flows.

What’s the latest?

Vietnam moved the bar this week: the draft Law on Data Security would ban exports of “core data” outright, require prior Ministry of Public Security approval for transfers of “important data” and “lar

How it developed

  1. AI Governance Becomes Operational Control, Data Sovereignty Demands Tighter Control Design
  2. Fraud and Cyber Converge, Continuous Assurance Goes Mainstream, and Sanctions Enforcement Tightens
  3. Continuous AI safety assurance, governed AI compliance operating models, and regulatory automation skills shift

Go deeper

Curated long-form picks on this trend — podcasts, videos, and analysis, by seniority.

Stay ahead in Compliance

Get the weekly Compliance brief in your inbox — the developments, what they mean by seniority, and what to do next.