Data, Technology & Compliance

Cross-Border Personal Data Transfers in Vietnam

越南个人数据跨境传输

For FDI companies, personal data rarely stays within Vietnam’s borders: group HR systems, cloud services of foreign providers, regional customer care centres — all are cross-border data flows. Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026) dedicates Article 20 to this activity, with obligations to prepare impact assessment dossiers and the specialised personal data protection authority’s inspection and transfer-suspension mechanisms. Violations of cross-border data transfer regulations face the highest administrative fine in the Law — up to 5% of the organisation’s immediately preceding year’s revenue (Clause 4 Article 8).

Which cases are considered cross-border data transfers

Clause 1 Article 20 lists three cases constituting cross-border personal data transfers. First, transferring data stored in Vietnam to storage systems located outside Vietnam’s territory — e.g. backing up customer data to the group’s data centre. Second, organisations and individuals in Vietnam transferring data to overseas organisations and individuals — e.g. sending personnel lists to the parent company or sharing customer data with partners. Third, agencies, organisations and individuals in Vietnam or abroad using platforms located outside Vietnam’s territory to process personal data collected in Vietnam.

The third case has a very broad scope and is most easily overlooked: using CRM software, analytics tools, recruitment platforms or email — if the provider’s servers are located outside Vietnam — may constitute cross-border data transfer, even if the company does not “actively send” data anywhere. When reviewing, list all technology providers and determine each provider’s server location.

Conditions for cross-border data transfers under Decree 356/2025

Law 91/2025 sets the framework in Article 20; Decree 356/2025/ND-CP details it in Article 18 with conditions stricter than Decree 13/2023. Accordingly, companies transferring data abroad must prepare cross-border data transfer impact assessment dossiers and notify the Ministry of Public Security (the specialised authority under the Ministry of Public Security per Article 33). In particular, companies must have a written agreement binding legal liability with the overseas data recipient, in which the recipient commits to protecting the lawful rights and interests of Vietnamese data subjects.

Cross-border data transfer impact assessment dossiers

Clause 2 Article 20 requires cross-border data transferors to prepare cross-border personal data transfer impact assessment dossiers, sending 01 original to the specialised authority within 60 days from the first day of transfer. This dossier is conducted once for the entire operation period (Clause 3 Article 20) and updated under Article 22 — every 06 months when there are changes, or immediately upon events such as reorganisation, provider changes or related business lines.

Dossier contents need to clarify: which data flows are transferred, who the recipient is and in which country, transfer purposes, data types (sensitive data needs separate identification), protection measures during transmission and storage abroad, and handling mechanisms when the recipient breaches commitments. The Government details dossier components, conditions, procedures and processes (Clause 7 Article 20). See the guide on personal data processing impact assessment dossiers to distinguish the two dossier types.

Cases not required to conduct impact assessments

Clause 6 Article 20 lists cases not required to conduct cross-border data transfer impact assessments. First, transfers of competent state agencies’ data. Second, agencies and organisations storing their employees’ personal data on cloud computing services — an exception of great practical significance for companies using cloud HR software. Third, data subjects transferring their own data across borders. Fourth, other cases under Government regulations.

This exception must be understood correctly: it only exempts the impact assessment dossier obligation for that storage activity, not other data protection obligations — companies must still comply with Article 25 (collect only necessary data; delete data upon contract termination, unless agreed or otherwise regulated by law). If the same cloud system also stores customer data or sensitive data beyond employee data, that data portion is not covered by the exception.

Inspection and the right to require transfer suspension

Clause 4 Article 20 grants the specialised authority the right to conduct periodic inspections no more than 01 time per year, or ad hoc inspections upon detecting violations or data leak/loss incidents. Clause 5 Article 20 provides that the specialised authority decides to require suspension of data transfers upon discovering data transferred for use in activities that may harm national defence and security.

If the data flow to group systems is ordered to stop, the company may have to operate temporarily on independent systems in Vietnam. Therefore, companies heavily dependent on cross-border systems should build technical contingency plans — e.g. separating Vietnamese data flows to operate independently when transfer suspension is ordered. Include this in the overall risk governance plan, together with the general Personal Data Protection Law compliance framework.

Sanctions: up to 5% of the immediately preceding year’s revenue

Clause 4 Article 8 sets the maximum fine for organisations violating cross-border personal data transfer regulations at 5% of the immediately preceding year’s revenue. Where there is no immediately preceding year’s revenue, or the revenue-based fine is lower than the VND 3 billion maximum in Clause 5 Article 8, the VND 3 billion level applies. This is the only revenue-based fine in the Law — for companies with revenue in the thousands of billions of dong, 5% may reach tens or hundreds of billions of dong — far exceeding the VND 3 billion fixed fine for other violations.

The Government regulates how to calculate “immediately preceding year’s revenue” and methods for determining revenue from violations (Clause 7 Article 8). This sanction applies to violations of cross-border data transfer regulations — including not preparing impact assessment dossiers, not notifying, or transferring data after being ordered to stop. The revenue-based penalty risk makes compliance in this area a direct financial risk governance measure.

Practical impact on FDI companies

Three common FDI company activity groups are directly impacted. First, group systems: personnel data, reports and customer data synchronised to ERP and HRM with servers at headquarters or regional data centres. Second, cloud and outsourced software: email, storage, CRM and analytics tools of global providers. Third, cross-border outsourcing: customer care and data processing located in other countries.

For each group, answer three questions: what data is being transferred (classified under Articles 3 and 4 of Decree 356/2025), to whom and where (recipient, country), and whether the current binding liability documents meet Article 18 of Decree 356/2025. Many FDI companies have operated these data flows for years without ever preparing dossiers under Decree 13/2023; with Law 91/2025 effective from 01/01/2026 and revenue-based fines, maintaining the status quo is an unacceptable risk.

Building written agreements with overseas data recipients

A written agreement binding liability with overseas recipients is a mandatory condition under Decree 356/2025, and also a tool protecting the company when incidents occur on the recipient’s side. A satisfactory document should include: data types and transfer purposes; commitment to process only for the stated purposes; equivalent security measures; prompt notification upon discovering incidents; compensation upon breach; data deletion/destruction upon cooperation termination.

For intra-group data flows, work with group legal to issue/amend intra-group data transfer agreements supplementing contents under Vietnamese law — global privacy policies are usually drafted under GDPR and may not cover the specific requirements of Article 20 and Article 18 of Decree 356/2025. With service providers, these contents should be included in the data processing addendum (DPA) attached to the main contract.

Transition provisions from Decree 13/2023

Under Clause 2 Article 39, cross-border data transfer impact assessment dossiers prepared under Decree 13/2023 and received by the specialised authority before the Law’s effective date continue to be used, without re-preparation; subsequent updates follow the new Law. Companies with dossiers under Decree 13/2023 should review and supplement new contents — especially the written liability-binding agreement with overseas recipients, a requirement tightened in Decree 356/2025.

Compliance roadmap and support from FLAT

Suggested compliance roadmap: (1) inventory all cross-border data flows, including “hidden” flows through platforms and software with servers outside Vietnam; (2) classify data and determine flows exempt under Clause 6 Article 20; (3) standardise written liability-binding agreements with overseas recipients; (4) prepare and send cross-border data transfer impact assessment dossiers within 60 days; (5) establish dossier update procedures when changing providers, systems or data flows; (6) build technical contingency plans for transfer suspension orders. See the in-depth article on cross-border personal data transfers. FLAT LAW FIRM supports FDI companies in reviewing cross-border data flows, drafting dossiers and standardising agreements with overseas recipients under Law 91/2025 and Decree 356/2025.

Frequently asked questions

Is using software from a foreign provider (servers abroad) a cross-border data transfer?

Possibly. Clause 1 Article 20 lists three cases, including using platforms located outside Vietnam’s territory to process personal data collected in Vietnam. If CRM, HRM, email or analytics software has servers located outside Vietnam, that activity may constitute a cross-border data transfer and trigger the dossier preparation obligation — except for exemptions in Clause 6 Article 20.

Must impact assessment dossiers be prepared for storing employee data on cloud services?

No, within the exception’s scope. Clause 6 Article 20 exempts the impact assessment obligation for storing employees’ personal data on cloud computing services. However, the exception only exempts the dossier obligation for that storage activity; companies must still comply with other employee data protection obligations under Article 25 of the Law.

What contents must the agreement with overseas data recipients have?

Under Article 18 of Decree 356/2025/ND-CP, there must be a written agreement binding legal liability with the overseas recipient, in which the recipient commits to protecting the lawful rights and interests of Vietnamese data subjects. The document should clearly specify data types, transfer purposes, security obligations, incident notification, compensation liability, dispute resolution mechanisms and data deletion/destruction upon cooperation termination.

Which authority can require companies to stop transferring data abroad?

The specialised authority (under the Ministry of Public Security per Article 33) decides to require suspension of cross-border data transfers upon discovering data transferred for use in activities that may harm national defence and security (Clause 5 Article 20). This authority also conducts periodic inspections no more than 01 time/year or ad hoc ones upon detecting violations or data leak/loss incidents (Clause 4 Article 20).

Must dossiers prepared under Decree 13/2023 be redone?

Not if the dossier was received by the specialised authority before Law 91/2025’s effective date (01/01/2026) — it continues to be used under Clause 2 Article 39. However, subsequent dossier updates follow the new Law; companies should review and supplement the tightened requirements in Decree 356/2025, especially the written agreement with overseas recipients.