Vietnam Data Law No. 60/2024/QH15: What Foreign Businesses Should Check

Digital data held by a business in Vietnam is now governed by a statutory framework. Vietnam Data Law No. 60/2024/QH15 was passed on November 30, 2024 and took effect on July 1, 2025. It governs digital data and how it is built, developed, protected, governed, processed and used, and it establishes the National Data Center, the National General Database, and rules for data products and services.

The law applies to Vietnamese organisations, to foreign organisations operating in Vietnam, and to foreign organisations that participate in or are connected with digital data activities in Vietnam. A foreign business may therefore be subject to the law without holding a licence or an office in the country.

Vietnam Data Law No. 60/2024/QH15
Vietnam Data Law No. 60/2024/QH15: What Foreign Businesses Should Check

Data Is Regulated by Category

Vietnam Data Law No. 60/2024/QH15 treats core data and important data differently from other digital data. These categories are determined by legal criteria and by the official list of core data and important data, which the Prime Minister issues and updates, not by how confidential a company considers the information to be.

Two consequences follow for management. The obligations depend on the category, so the business must identify what it holds before deciding which procedures apply. These categories are also separate from sensitive personal data under Vietnam’s personal data protection rules. A dataset may be subject to both frameworks, or to neither.

Cross-Border Rules Apply to Processing as Well as Transfer

The transfer of data into Vietnam and the processing of foreign data in Vietnam are permitted activities, and the State protects the lawful rights and interests connected with them.

The transfer of core or important data out of Vietnam is treated differently. The rules cover data transferred from storage in Vietnam to a system located abroad, data provided to a foreign organisation, and data processed on a platform located outside Vietnam.

The third situation is easily overlooked. Where a Vietnamese organisation uses a platform located outside Vietnam to process core or important data, the activity can fall within the cross-border rules even if the business does not regard it as a conventional data transfer.

The implementing decree sets out what each category requires, and the two procedures are not identical. Core data goes through assessment by the competent authority before the data governing body decides on the transfer. For important data, prior approval is generally not required, but an impact assessment dossier must generally be submitted 15 days before the cross-border processing. Exceptions apply to specified cases.

How the Data Law Applies Alongside the Personal Data Rules

Overlapping datasets were an early source of uncertainty. The implementing rules were amended so that where core or important data is also personal data, its protection follows the personal data framework.

For cross-border processing or transfer of that overlapping data, the business prepares the assessments required under the personal data framework instead of carrying out a second assessment under the Data Law rules. The personal data obligations are unchanged, and the Data Law framework continues to apply to core or important data that is not personal data. Classification is therefore an early step in any review of Vietnam data compliance.

Data Exchanges Are Now Regulated

The operation of data exchanges is now subject to a separate regulatory framework under Decree 314/2026/ND-CP, effective September 25, 2026. Two requirements are relevant to foreign businesses.

A foreign legal entity trading through a regulated data exchange must have a local presence in Vietnam, which can be a commercial presence, a branch, or a representative office, subject to applicable treaty provisions. The choice of presence therefore forms part of the business’s wider Vietnam market entry strategy, rather than only a question about how the data transaction will be structured.

The prohibition on buying and selling personal data continues to apply. A listing on an exchange does not establish a right to trade the data or to use it abroad.

What This Means for the Business

Four checks are worth making.

  1. Confirm whether the business holds data that meets the criteria for core or important data, using the legal criteria and the current official list rather than an internal confidentiality classification.
  2. Identify whether core or important data is processed on platforms located outside Vietnam, since this can fall within the cross-border rules even where the arrangement is not regarded as a conventional data transfer.
  3. Where a dataset is both personal data and core or important data, confirm which framework applies before preparing any filing.
  4. If the business plans to buy or sell data, check the participation conditions and the local presence requirement before committing to a transaction.

Enforcement is governed by a separate framework. The Vietnam personal data protection penalties include fines calculated as a percentage of prior-year revenue in the Vietnamese market for specified serious cross-border violations, alongside fixed fines and corrective measures for other violations.

Frequently Asked Questions

Q1: Does Vietnam Data Law No. 60/2024/QH15 apply to a company with no office in Vietnam?

Yes, it can apply. The law covers foreign organisations that participate in or are connected with digital data activities in Vietnam, so the answer depends on the activity rather than on registration.

Q2: Does the Data Law require data to be stored in Vietnam?

Storage obligations arise under the cybersecurity rules and apply to defined service providers, not to every business holding data. The Data Law sets assessment procedures for cross-border transfers of core and important data.

Q3: Is prior approval needed for every transfer abroad?

No. What is required depends on the data category and the activity. Core data and important data do not follow identical procedures, and personal data follows its own framework.

About the Author

Hanh Pham is a Legal Research Specialist at ANT Lawyers with more than 10 years of experience, supporting legal teams through regulatory research, authority liaison, documentation review, and knowledge development. She has been trained in corporate, civil law and related areas. This article has been reviewed by Tuan Nguyen, Managing Partner, ANT Lawyers; member of the Hanoi Bar Association and Vietnam Bar Association.

About ANT Lawyers, a Law Firm in Vietnam

Founded in 2012, ANT Lawyers is a Vietnam law firm with offices in Hanoi, Ho Chi Minh City and Da Nang. Our data compliance lawyers advise on personal data protection, data processing, cross-border data transfers, cybersecurity and compliance requirements in Vietnam. We combine legal analysis with practical understanding of Vietnam’s regulatory environment and local administrative practice.

General Disclaimer

This article is for general informational purposes only, does not constitute legal advice, and does not create a lawyer-client relationship. Vietnamese laws, regulations and administrative practice change over time, and the correct position for any matter depends on its specific facts and the rules in force when action is taken. Verify the current position before relying on anything stated here, and consult qualified counsel on your specific situation.

How ANT Lawyers Could Help Your Business?

You could reach ANT Lawyers for advice via email ant@antlawyers.vn or call our office at (+84) 24 730 86 529

Contact us to schedule your consultation.

A

We are available at offices in central of Hanoi, Ho Chi Minh City and Da Nang that help cover through out Vietnam.

Tel: +84 24 730 86 529
Email: ant@antlawyers.vn