Vietnam Data Compliance:7 Decisions for Foreign CompaniesDoing Business in Vietnam

For foreign companies, Vietnam data compliance rests mainly on the Data Law, the Personal Data Protection Law, and the Cybersecurity Law, together with their implementing decrees and any sector rules. They govern how a business collects, uses, shares, transfers, stores, and protects information. The duties depend on the data, the activity, and the company’s role. Vietnam continues to legislate in this area, so the starting point for management is not a fixed list of rules but a set of decisions the business needs to get right.

Decisions about data affect how a foreign company enters the Vietnamese market, operates, and works with others. Management needs to know what information the company may use, who may access it, and what responsibilities follow. The seven decisions below cover the main questions from collection and use through sharing, overseas transfers, storage, and deletion.

Vietnam Data Compliance
Vietnam Data Compliance: 7 Decisions for Foreign Companies Doing Business in Vietnam

Why Vietnam Is Strengthening Data Compliance Now

Data has commercial value. E-commerce businesses use purchase histories and browsing information to understand demand and improve sales. AI systems can use large datasets for training, prediction, and product development. The questions are who may use this information, who benefits from it, and how misuse can be controlled.

Vietnam’s policy combines data sovereignty, economic development, and protection of individuals. Here, data sovereignty means Vietnam’s authority to govern data within its legal jurisdiction. That includes the use of valuable national data, access by overseas organizations, and accountability when something goes wrong.

The official text of Resolution 57-NQ/TW links national digital sovereignty with data markets and AI development. The Politburo adopted this policy on December 22, 2024, to advance science, technology, innovation, and national digital transformation. It sets a policy direction; legal obligations come from legislation.

The Data Law expressly treats data as a resource and supports its development into an asset. The main data, privacy, and cybersecurity laws took effect during 2025 and 2026. Together, they give Vietnam data compliance a wider role in business planning, alongside the protection of customer and employee information.

For management, this means checking rights to use data before investing in analytics, AI tools, or a new digital service. A useful dataset may still carry restrictions on reuse, sharing, or overseas processing.

Quick Reference

Data Law: Law No. 60/2024/QH15 took effect on July 1, 2025. It covers digital data, rights to use it, and core and important data.

Personal Data Protection Law: Law No. 91/2025/QH15 took effect on January 1, 2026. It governs information about identifiable individuals.

Cybersecurity Law: Law No. 116/2025/QH15 took effect on July 1, 2026. It covers cybersecurity duties, including local storage for covered service providers.

Sensitive personal data, important data, and core data are different categories. Review domestic sharing, cross-border transfers, and local storage duties separately.

Before using or sharing data, it is important to confirm its source, the permitted purpose, the recipients, and the responsible company. Keep contracts, assessments, and operational controls consistent with those answers.

7 Decisions for Foreign Companies Doing Business in Vietnam

What Data Does Your Company Hold?

The first decision is how far the review reaches and who produces the answer. Most companies hold more data than management expects, and much of it sits outside company systems. Human resources holds recruitment files and payroll records. Sales keeps customer details in a company system and in separate spreadsheets. Production information may sit in equipment software or with a maintenance supplier. Customer, operational, and employee information all count.

A data inventory turns this into something the business can work with: a record of what is held and what happens to it. It should cover shared drives, messaging tools, backups, and copies sent outside the company, and it should record where the information came from, who uses it, and how long it is kept. It is also the point at which a business finds out whether its records are accurate and whether it can correct outdated information.

The Data Law covers digital data more broadly than personal information. Personal data concerns identifiable individuals. A business may also hold equipment readings, product specifications, and commercial forecasts that identify no one.

The legal categories then matter. “Sensitive personal data” is different from “important data” and “core data” under the Data Law. Important and core data are identified using the legal criteria and the applicable government list. Information does not become core data simply because the company treats it as confidential.

Before approving a new use of data, ask what information the business needs, whether it has the right to use it, who will have access, and what they may do with it.

Which Rules Apply to Your Business?

Vietnamese rules can apply to a company with no office in Vietnam. They could reach overseas organizations involved in processing the personal data of Vietnamese citizens, so the question is not where the company is registered but whose data it handles and what it does with it.

Several laws may also apply to the same activity at once for sensitive area i.e. bank or healthcare business. That overlap is normal and it is why the review works better activity by activity than law by law.

Responsibility then depends on the company’s role. A controller decides why and how personal data is processed. A processor handles it on another party’s behalf, and a business may take different roles in different services. The contract wording should match what each party actually does, because the role determines who must prepare and maintain any required impact assessment.

Size affects some duties but not the overall picture. Small enterprises and startups may choose not to apply certain assessment and staffing requirements for a limited period, and household and micro businesses have their own exemptions. None of this is available to a business that provides processing services, handles sensitive personal data, or processes data about a large number of people. The relief is temporary and the other duties continue.

For a foreign company, Vietnam data compliance becomes unclear when work is divided between the local office and headquarters. The local team may believe headquarters has completed the review, while headquarters expects the local team to handle Vietnamese requirements. Agree who will assess each important activity and who will complete the resulting work.

An existing global privacy program can help. Its records and security controls may already cover much of the operation. The remaining task is to compare them with Vietnamese requirements and deal with any gaps.

Can You Use the Data for This Purpose?

Wanting the data is not a legal basis for using it. For personal data, the company must identify a basis recognised by Vietnamese law, which means consent or one of the specified circumstances where processing may take place without it.

Where consent is the basis, it must be a real choice. Silence and preselected settings do not establish valid consent, and the company needs to keep evidence of what the person agreed to. People need to understand what information will be used, for which purposes, and by whom. Sensitive personal data requires additional care and additional information.

Collection limits follow from the same question. A form or software system often allows the company to collect more than it needs, so it is worth asking why each field is there. If the business cannot explain how it uses the information, it should consider whether to collect or keep it at all.

A new purpose needs its own check. Contact details collected to deliver orders are not automatically available to a regional marketing team, and the answer may change depending on who receives the list and whether the information leaves Vietnam. Run that check before the data moves, not afterwards.

Non-personal information raises a different question: does the company have the right to use it? Data received under a contract or license may be restricted to an agreed purpose, so the limits need checking before sharing, reselling, or reusing it. Possession of data does not, by itself, allow every use.

Can You Share or Transfer Data Within Vietnam and Overseas?

The first is whether the company may move the data at all. The second is whether a copy must stay in Vietnam. A transfer assessment does not answer the storage question, and the storage rules do not permit a transfer.

Sharing within Vietnam still needs a basis. Confirm the recipient, the purpose, and the legal or contractual basis, and agree who protects the information and whether it may be passed on.

Cross-border arrangements are wider than they first appear. Overseas access by headquarters, group companies, suppliers, and subcontractors counts, as do cloud storage and backups. Access or processing from abroad can raise transfer requirements even when the main server stays in Vietnam.

Under the Personal Data Protection Law, cross-border transfers generally require an impact assessment file, with exceptions for defined activities. The file describes the transfer, its risks, and the measures used to address them, and it must be prepared and submitted when required. This is not a universal requirement to obtain prior approval for every transfer.

Exceptions are narrow and specific. They cover defined activities rather than categories of company, so an exemption that fits one arrangement will not automatically cover other overseas uses or sharing within a corporate group. Record the reason for relying on one.

For core or important data that is not personal data, the Data Law framework sets separate cross-border assessment procedures. Where the transferred data is also personal data, the personal data protection assessment requirements apply instead. Confirm the data category before deciding which assessments and filings are needed.

Local storage is where the market entry question arises. The Cybersecurity Law addresses enterprises providing services over telecommunications networks, the Internet, and value-added online services in Vietnam. Providers that collect, use, analyze, or process the user data described in the law, including personal information, information about users’ relationships, and data generated by users in Vietnam, must store that data in Vietnam for the period set by the Government. Foreign enterprises within that group must also establish a branch or representative office here.

For a foreign provider, that duty affects whether and how to enter the market, not just where to put a server. Consider it alongside the wider Vietnam market entry strategy, including the activities the local presence may carry out.

Buying an overseas service is different from providing one. Using cloud software does not automatically make every customer subject to the same local storage or local presence requirements, so separate the company’s own duties from the provider’s.

Before approving a sharing or transfer arrangement, confirm the permitted use, required assessments, and any local storage duty. Keep that decision with the contract and review it if recipients, access locations, or purposes change.

What Should Your Supplier Contracts Cover?

Can the supplier use your data to develop its products? Can it share the data with subcontractors? Could it use the information to train an artificial intelligence system? A promise to keep information secure answers none of these, so read the supplier’s terms alongside its description of the service and see which questions are left open.

The agreement should set out permitted uses, access, locations, and security responsibilities, and it should explain how the supplier will help with individual requests and data incidents. Where personal data is involved, the parties need a written arrangement that reflects their actual roles, because the contract is what allocates responsibility between them.

The timing of cooperation matters as much as its existence. If a supplier only promises to report a leak after finishing its investigation, the customer may struggle to meet its own deadlines. Agree how early information will be shared while the investigation continues.

The end of the service deserves the same attention. The company may need its records returned in a usable format before access is closed, so agree what will be deleted, what may need to be retained, and how copies held by subcontractors will be handled.

When buying or licensing data, check whether the seller has the right to supply it for your intended use. Confidentiality, licensing, and ownership also raise questions about intellectual property in Vietnam. A confidentiality agreement can restrict disclosure. It does not, by itself, give either party the right to collect or transfer personal information.

Buying or selling personal data is prohibited unless the law provides otherwise, and data exchanges do not remove that restriction. Foreign legal entities trading through a regulated data exchange must also have a local presence in Vietnam, which can be a commercial presence, branch, or representative office, subject to applicable treaty provisions. A listing does not, by itself, establish the right to trade the data or use it abroad.

How Will You Handle Requests and Data Incidents?

Much of Vietnam data compliance is tested when someone asks a question or reports a problem. An employee receiving a deletion request or discovering a possible leak should know whom to contact, and the person receiving that report needs authority to bring in the right colleagues and suppliers.

Requests may concern access, correction, deletion, withdrawal of consent, or limits on processing. Verify the person’s identity first, then establish what they are asking for, locate the information, and assess the applicable right and any exception. Deletion in particular may involve the local team, headquarters, and several suppliers.

Some records must be kept even when someone asks for deletion, because other laws require their retention. This happens most often with staff records, where employment law in Vietnam sets its own requirements alongside the personal data rules.

If information is exposed, the first steps are stopping further access, preserving evidence, and recording when the incident was discovered. The response team then needs to work out what happened, who may be affected, and what harm could follow. Supplier and customer contracts may require notifications of their own.

The Personal Data Protection Law sets a 72-hour notification duty to the data protection authority for specified violations that may harm protected interests, including national security, public order, and an individual’s life, health, honor, dignity, or property. The period runs from discovery, which means the deadline can fall well before the investigation is complete. Decide which duties apply as early as possible rather than waiting for a full picture.

Not every technical incident triggers that duty in the same way. Processors must promptly notify the controller, affected individuals may also need to be told, and the incident records still have to be kept.

When an authority requests information, verify the request and its legal basis, confirm what must be provided and by when, keep a record of the response, and send the information securely.

To see whether these arrangements work, ask the team what it would do if a supplier exposed a customer file on a Friday evening. Can it reach the right people and obtain the information needed to act?

Who Is Responsible for Data Security and Ongoing Compliance?

Vietnamese law requires organisations to have data protection personnel, so this is an obligation rather than an internal preference. A company may appoint an officer or an internal unit, engage a service provider, or combine both, and the personnel must meet the conditions set by the rules. Eligible small enterprises and startups may set this duty aside for a limited period. Where the business handles core or important data, a responsible person and a data safety unit are required under the data legislation as well.

Security measures then have to fit the information and the risks. Limit access to people who need it, protect accounts and systems, and test backup recovery. Staff should know the rules for handling information and how to report a concern.

The law also expects the company to be able to demonstrate what it did. That is the purpose of the data inventory, the legal basis for processing, notices, consent records, required assessments, supplier agreements, and incident records. These need to be kept current and accessible, because they are the evidence available if an authority asks.

Retention follows the purpose of the data and any legal requirement to keep it. Decide how information will be deleted or made anonymous once it is no longer needed, then check that this actually happens in company systems, exported files, backups, and supplier records. Keep a way to suspend deletion when records must be preserved for a legal matter.

Compliance work also has to keep pace with the business. New software, an acquisition, or a different overseas support team can change who receives information and what they do with it, and these changes often take place without a legal review. Procurement and project teams should know when to ask for one, preferably before signing the contract or uploading the data.

The consequences are financial as well as operational. For organizations, the Personal Data Protection Law sets a general fine ceiling of VND 3 billion for personal data violations. Special ceilings reach 10 times the proceeds from unlawful personal data trading and, for the most serious cross-border transfer violations, 5% of prior-year revenue. These are legal ceilings, not automatic fines, and the amount depends on the conduct and the relevant penalty rules.

Financial exposure is not the only consequence. Corrective measures can also require changes to data use, records, or systems, and these obligations form part of the framework on Vietnam personal data protection penalties.

Step by Step To Review Vietnam Data Compliance

Knowing what to examine is one thing; getting it done across a business is another. The steps below turn the seven decisions into a review a manager can run on a single process, then repeat elsewhere. They describe a management sequence, not a statutory filing procedure.

Step 1. Choose a process and name a coordinator

Start with a business activity where data use is important or a significant change is planned. Name a person who can obtain answers from the local team, headquarters, and suppliers. Agree what the review will cover and when management will consider the findings.

Step 2. Follow the data through the process

Record what is collected, why it is needed, who can access it, and where it goes, including overseas support, exports, backups, and deletion. Check a sample against actual system settings and contracts rather than against the written policy. Use masked examples where possible, so that the review itself does not create unnecessary copies of personal data.

Step 3. Identify the duties and the missing evidence

Check the data categories, each party’s role, the permitted uses, and any overseas transfer or local storage duties, then confirm which notices, contracts, assessments, or filings this arrangement requires. Duties can arise under more than one law at the same time, so record unresolved questions and seek advice on them rather than treating a standard checklist as proof of compliance.

Step 4. Assign and complete the changes

Give each action an owner, a due date, and a record showing it was completed. Changes may include limiting access, updating a notice, or agreeing supplier assistance. If a proposed new use has no confirmed legal basis, resolve that question before the use begins.

Step 5. Test the result

Take the team through two scenarios: an access request from an individual, and a data leak at a supplier. Confirm that they can locate the records, reach the person responsible, and act within the relevant deadline. Correct whatever fails the test and keep the results as evidence. Repeat the review when the process, the provider, or the purpose changes, and when new data legislation takes effect.

Frequently Asked Questions on Vietnam Data Compliance

Q1: Do data transfer rules apply only when files are sent abroad?

No. Review domestic sharing as well as cross-border transfers. Overseas storage, remote access, and processing arrangements may engage cross-border requirements even without moving the main server. The relevant duties depend on the data, the parties, and the activity.

Q2: Can a foreign company use cloud services outside Vietnam?

Yes, provided the arrangement meets the rules that apply to the service and data. Check overseas transfer requirements and any local storage or sector duties. Using a well-known provider does not settle those questions on its own.

Q3: Must data be stored in Vietnam?

Some data must be stored locally when the provider and activity fall within the cybersecurity rules. Telecommunications, Internet, and value-added online services need particular attention. Sector rules may add other duties. There is no general rule requiring every foreign company to keep every type of data exclusively in Vietnam.

Q4: Does GDPR compliance satisfy Vietnamese requirements?

No. GDPR documents and controls can help with the review, but Vietnamese law has its own requirements. The company still needs to check whether its activities and documents meet those rules.

Q5: Does consent allow any use of personal data?

No. Consent must be valid and cover the proposed use. Other duties and prohibitions still apply. Before changing the purpose or sharing information with a new recipient, check whether the new arrangement is permitted.

Q6: Can data be shared between companies in the same group?

Sharing may be possible, but being in the same group is not enough by itself. Check why the recipient needs the information, what it will do with it, and the legal basis. Overseas transfer requirements may also apply.

Q7: Can customer data be used to train an AI model?

Sometimes, but collecting information for one business purpose does not automatically permit AI training. Check the legal basis, stated purpose, supplier terms, and any overseas access. Removing names alone may not prevent people from being identified. Assess the actual dataset and proposed use before making it available.

Q8: What are the penalties for non-compliance?

For organizations, the Personal Data Protection Law sets a general ceiling of VND 3 billion for personal data violations. Special ceilings reach 5% of prior-year revenue in Vietnam for the most serious cross-border transfer violations and 10 times the proceeds from unlawful personal data trading. These are maximum limits; the actual fine depends on the conduct and the penalty rules. Corrective measures may also follow.

Conclusion

At the next management meeting, choose one process and name the person who will lead its review. Ask for the data flow, unresolved questions, and actions needed before approving a new arrangement. That turns Vietnam data compliance into decisions the business can follow through.

About the Author

Tuan Nguyen is the Managing Partner and founder of ANT Lawyers, with more than 20 years of experience across legal practice, management and compliance. He advises foreign companies, investors and manufacturers on corporate, commercial, international trade, regulatory and dispute-related matters in Vietnam. He holds an LLB from Hanoi National University School of Law and an MBA from Warwick Business School, and is an Associate Member of the Chartered Institute of Arbitrators.

About ANT Lawyers, a Law Firm in Vietnam

Founded in 2012, ANT Lawyers is a Vietnam law firm with offices in Hanoi, Ho Chi Minh City and Da Nang. Our data compliance lawyers advise on personal data protection, data processing, cross-border data transfers, cybersecurity and compliance requirements in Vietnam. We combine legal analysis with practical understanding of Vietnam’s regulatory environment and local administrative practice.

General Disclaimer

This article is for general informational purposes only, does not constitute legal advice, and does not create a lawyer-client relationship. Vietnamese laws, regulations and administrative practice change over time, and the correct position for any matter depends on its specific facts and the rules in force when action is taken. Verify the current position before relying on anything stated here, and consult qualified counsel on your specific situation.

How ANT Lawyers Could Help Your Business?

You could reach ANT Lawyers for advice via email ant@antlawyers.vn or call our office at (+84) 24 730 86 529

Contact us to schedule your consultation.

A

We are available at offices in central of Hanoi, Ho Chi Minh City and Da Nang that help cover through out Vietnam.

Tel: +84 24 730 86 529
Email: ant@antlawyers.vn