Legal services for domestic and FDI companies
Cross-Border Personal Data Transfer
Sending HR data to a foreign parent company, using Google Workspace or Microsoft 365, storing on AWS, hiring foreign partners to process customer data — all can constitute “cross-border personal data transfer” under Article 20 of the Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026). From this point, companies must secure data subject consent, prepare a Cross-Border Personal Data Transfer Impact Assessment Dossier, and submit it to the personal data protection authority under the Ministry of Public Security within 60 days from the first transfer date. Violations can be fined up to 5% of the preceding year’s revenue under Decree 330/2026/NĐ-CP. FLAT LAW FIRM helps review all data flows, draft impact assessment dossiers, finalize binding responsibility documents with recipients, and build internal policies so companies comply right from the start.

Cross-border personal data transfer: which companies should care?
- Multinational groups and FDI companies transferring HR and customer data to foreign parent companies or regional data centers.
- Companies using platforms hosted outside Vietnamese territory to process data collected in Vietnam: Google Workspace, Microsoft 365, AWS, international HRM/CRM systems.
- Companies hiring foreign partners to process data: data analytics outsourcing, customer care services, audits, consulting with personal data access.
- Companies storing personal data on cloud services of foreign providers.
- Companies with websites or apps collecting data of Vietnamese users and syncing it to servers abroad.
Common legal issues companies face
The most common mistake is thinking only “sending files abroad” counts as cross-border data transfer. Under clause 1, Article 20 of the Personal Data Protection Law 91/2025/QH15, using platforms hosted outside Vietnamese territory to process data collected in Vietnam — such as corporate email on Google Workspace or Microsoft 365, data stored on AWS — also constitutes cross-border personal data transfer. Many companies are in this situation without ever having prepared any dossier.
The second mistake is misunderstanding the exemption scope. The Law exempts the impact assessment dossier obligation for “agencies and organizations storing their own employees’ personal data on cloud computing services” — but this exemption applies only to storage. If the foreign parent company also processes that HR data (performance reviews, centralized payroll, HR analytics…), companies need to reassess each specific data flow rather than defaulting to exemption.
The third mistake is having generic employee/customer consent but no separate consent for the cross-border transfer purpose. The law requires consent to be clear and specific for each purpose, and data subjects must be notified that their data is transferred abroad, who receives it, and for what processing purposes — missing any of these elements can attract penalties.
See Cross-Border Personal Data Transfer (FLAT LAW FIRM’s practice article).
Three cases treated as cross-border personal data transfer
Clause 1, Article 20 of the Personal Data Protection Law 91/2025/QH15 identifies three groups of acts:
- Transferring data stored in Vietnam to data storage systems located outside the territory of the Socialist Republic of Vietnam.
- Agencies, organizations, or individuals in Vietnam transferring personal data to organizations or individuals abroad — e.g., sending HR lists or customer files to parent companies, partners, or service providers abroad.
- Using platforms outside Vietnamese territory to process personal data collected in Vietnam — e.g., email systems, cloud storage, management software hosted on servers abroad.
Companies should start by inventorying all data flows: what data, whose, where it sits, who can access it from abroad. This step cannot be skipped before assessing compliance obligations.
Compliance conditions and sequence
- Securing data subject consent for the cross-border transfer purpose (Article 9 of Law 91/2025/QH15): consent must be clear and specific for each purpose, printable and reproducible in writing — including in electronic form or a verifiable format. Silence or non-response does not count as consent. Data subjects must also be notified that their data is transferred abroad, who receives it, and for what processing purposes. Some cases allow processing without consent (emergencies, legal obligations…) — each specific case needs cross-checking.
- Establishing binding responsibility documents between the transferring and receiving parties: contracts or transfer instruments clearly stating each party’s personal data protection responsibilities, purposes, scope, data types, processing/storage/deletion periods, and coordination mechanisms when violations occur. For multinational groups, this is typically an intra-group data transfer agreement.
- Preparing the Cross-Border Personal Data Transfer Impact Assessment Dossier under Article 18 of Decree 356/2025/NĐ-CP, with three components (see table below). This dossier differs from the personal data processing impact assessment dossier for data processing in general.
- Submitting the dossier to the personal data protection authority under the Ministry of Public Security: 01 original within 60 days from the first transfer date. The dossier must be updated when changes occur and kept available for inspections and assessments by competent authorities.
- Applying security measures and safety plans during and after transfer: encryption, access control, and data protection standards applied at the recipient.
The sequence above applies to the general case. Depending on the transfer model (intra-group, outsourcing, cloud…), the order and focus may differ — contact FLAT LAW FIRM for a tailored roadmap.
Components of the Cross-Border Personal Data Transfer Impact Assessment Dossier
| Component (clause 2, Article 18 of Decree 356/2025/NĐ-CP) | Key content |
|---|---|
| Impact assessment report using Form No. 09 (Appendix of Decree 356/2025/NĐ-CP) | Information and contacts of transferring, receiving, processing, and related parties; personal data protection departments/personnel; purposes, data types, details of transfer/processing activities, and data flow diagrams; obtaining data subject consent; storage, deletion, and destruction policies; post-transfer safety plans, protection measures and standards applied; the recipient’s storage/processing system diagrams |
| Copy of the data transfer contract or instrument | Showing the binding obligations and responsibilities between cross-border transferring and receiving organizations and individuals |
| Policies, procedures, regulations, forms, and related documents | Personal data protection documents of the party conducting cross-border transfers (privacy policies, internal procedures, consent forms…) |
Cases exempt from preparing the impact assessment dossier
Clause 6, Article 20 of Law 91/2025/QH15 exempts the dossier obligation for four groups:
- Cross-border personal data transfers by competent state agencies.
- Agencies and organizations storing their own employees’ personal data on cloud computing services.
- Data subjects themselves transferring their own personal data across borders.
- Other cases as provided by the Government.
Important note: exemption from the dossier does not mean exemption from all obligations. Exempted companies must still comply with other personal data protection principles (security, purpose limitation, data subject rights…). Especially for the “employee data storage on cloud” exemption: if the foreign recipient also processes beyond mere storage, companies should reassess rather than defaulting to exemption — this is a point inspection teams scrutinize closely.
What does FLAT LAW FIRM do?
- Reviewing and inventorying data flows: identifying which data is being transferred abroad, under which of the three Article 20 groups, and whether exemptions apply.
- Drafting the cross-border transfer impact assessment dossier: the Form No. 09 report, data flow descriptions, risk assessments, and safety plans — see our practice article.
- Drafting binding responsibility documents: data transfer contracts with foreign partners; intra-group data transfer agreements (intra-group agreements) for FDI companies.
- Finalizing consent and notification mechanisms: consent forms for cross-border transfer purposes and data subject notifications — ensuring clarity, specificity, and verifiability under Article 9.
- Building internal policies: personal data protection policies, data subject request handling procedures, incident response procedures for data leaks/loss.
- Representing before competent authorities: preparing and submitting dossiers to the personal data protection authority under the Ministry of Public Security; coordinating on supplement requests or inspections.
- Internal training: training personnel on personal data protection obligations in daily operations — see Ongoing Legal Advisory and Ongoing Legal Advisory for FDI Companies.
Implementation process
- Receiving information: the company’s operating model, systems in use (email, cloud, HRM/CRM), current outbound data flows.
- Inventory and classification: data flow mapping (data types, subjects, recipients, purposes, transfer forms), cross-checked against the three cases in clause 1, Article 20 and the four exemptions in clause 6.
- Compliance gap analysis: consent, binding documents, security measures, existing/missing dossiers.
- Drafting dossiers: the Form No. 09 impact assessment report, transfer contracts/instruments, accompanying policies and forms.
- Finalizing consent and notification mechanisms for data subjects before transfer.
- Submitting the dossier to the personal data protection authority under the Ministry of Public Security within 60 days from the first transfer date; tracking and handling supplement requests (if any).
- Handover and maintenance: internal policies, dossier update schedules when changes occur, incident response procedures.
Documents clients should prepare
- List of systems processing/storing personal data (email, cloud, HRM/CRM/ERP, websites/apps).
- Description of current outbound data flows: what data, whose, to whom, where, by what means.
- Contracts with foreign service providers (Google, Microsoft, AWS, outsourcing partners…).
- Intra-group data sharing agreements (if any).
- Current privacy policies and internal data regulations (if any).
- Employment contract templates and confidentiality agreements with employees.
- Contact information of IT and legal personnel.
Expected time and cost
Completion time depends on data flow complexity: companies using a few common cloud platforms usually complete review and dossiers within weeks; groups with many parallel transfer flows (intra-group, outsourcing, multiple countries) need longer for full inventory and drafting. Note the legal milestone: dossiers must be submitted to the authority within 60 days from the first transfer date — companies already transferring without dossiers should start immediately to avoid prolonged violation.
Service fees are quoted specifically after scoping (number of data flows, recipients, multinational group factors) — please contact us for a quote.
Notes for FDI companies
- Transferring data to the parent company: this is the typical case of point b, clause 1, Article 20 (Vietnam-based organizations transferring data to organizations abroad). Companies need an intra-group data transfer agreement clearly stating the parent company’s data protection responsibilities, plus mechanisms for Vietnamese employees/customers to exercise their rights after data is transferred.
- HR data vs. customer data: the two groups differ in sensitivity and processing purposes — impact assessment dossiers should separate each flow rather than merging them into one sketchy report.
- Global shared systems: many groups require subsidiaries to use shared HRM/CRM hosted abroad. In this case, the Vietnamese company remains the party obligated to comply with Vietnamese law — “global policy” cannot replace domestic dossier requirements.
- Multilingual coordination: consent forms, data subject notifications, and internal policies often need bilingual versions to satisfy both Vietnamese law and group processes. FLAT LAW FIRM works in Vietnamese, Chinese, and English — see Foreign Investment in Vietnam and Corporate Legal.
Risks and sanctions for violations
- Fines of VND 50–100 million (Decree 330/2026/NĐ-CP) for acts including: not establishing binding transfer responsibility contracts/documents between transferring and receiving parties; not securing data subject consent for cross-border transfer purposes or not notifying data subjects; not applying appropriate security measures or lacking post-transfer safety plans; obstructing inspections; continuing transfers after a stop order; not notifying and requiring the recipient to stop processing upon discovering violations or data leak/loss incidents.
- Revenue-based fines on the preceding fiscal year’s revenue in the Vietnamese market for transferring data across borders without preparing an impact assessment dossier, concealing or misdeclaring data flows causing personal data leaks/loss, or continuing transfers after a stop order: 1–2% of revenue (leak/loss of 10,000 to under 100,000 Vietnamese citizen data subjects); 2–3% (100,000 to under 1,000,000 subjects); 3–5% (1,000,000 subjects or more, or harm to national defense and security).
- Maximum: 5% of the preceding year’s revenue for organizations violating cross-border personal data transfer rules (clause 6, Article 8 of Law 91/2025/QH15).
- Beyond fines: depending on the nature and severity of violations, additional sanctions and remediation orders may apply; damages must be compensated under the law.
With fines calculated as a percentage of revenue, compliance from the start is always cheaper than post-violation remediation — especially for companies with large data volumes.
Legal updates through September 2026
The Personal Data Protection Law 91/2025/QH15, effective 01/01/2026, is the first comprehensive law on personal data protection in Vietnam.
Decree 356/2025/NĐ-CP (issued 31/12/2025, effective 01/01/2026) details and guides implementation of the Law, fully replacing Decree 13/2023/NĐ-CP. Key new points: administrative procedures standardized with 10 forms (including Form No. 09 for the cross-border transfer impact assessment report); separate provisions on cloud computing, artificial intelligence, blockchain; stricter conditions for data processing service businesses.
Decree 330/2026/NĐ-CP provides administrative sanctions in cybersecurity and personal data protection, effective 19/8/2026 — the first to set specific sanctions, including revenue-based fines up to 5% for cross-border data transfer violations.
Companies that prepared dossiers under Decree 13/2023/NĐ-CP should review everything to ensure alignment with Law 91/2025 and Decree 356/2025 — many forms and requirements have changed. Page content should be cross-checked against the instruments in force at the time of the procedure.
Why choose FLAT LAW FIRM?
We approach compliance as it should be: we review the company’s actual operations first, then design fitting dossiers and documents — rather than applying one template set to every client. With experience advising FDI companies and multinational groups, we understand how to reconcile group global policies with mandatory Vietnamese law requirements. See Corporate Legal.
Frequently Asked Questions
Does using Google Workspace / Microsoft 365 / AWS count as transferring data abroad?
Yes. This falls under “using platforms outside Vietnamese territory to process personal data collected in Vietnam” (point c, clause 1, Article 20 of Law 91/2025/QH15) and requires full compliance: data subject consent, binding responsibility documents, preparing the Impact Assessment Dossier and submitting it to the authority under the Ministry of Public Security — unless it falls under one of the four exemptions in clause 6, Article 20.
What must be done when the parent company requires sending HR data to the overseas head office?
This is the case of a Vietnam-based organization transferring data to an organization abroad. Companies need to: (1) secure employee consent for the cross-border transfer purpose and clearly notify the receiving organization and processing purposes; (2) sign an intra-group data transfer agreement stating the parent company’s data protection responsibilities; (3) prepare the Cross-Border Personal Data Transfer Impact Assessment Dossier; (4) submit the dossier to the authority under the Ministry of Public Security within 60 days from the first transfer date. Note: the “employee data storage on cloud” exemption applies only to storage — if the parent also processes data (reviews, analytics…), each case needs reassessment.
What does the cross-border transfer impact assessment dossier include?
Under clause 2, Article 18 of Decree 356/2025/NĐ-CP, the dossier has three components: (1) the impact assessment report using Form No. 09 in the Decree’s Appendix; (2) a copy of the data transfer contract or instrument showing binding obligations and responsibilities between transferring and receiving parties; (3) related personal data protection policies, procedures, regulations, forms, and documents.
How long is the deadline for submitting the dossier to the Ministry of Public Security?
The transferring party submits 01 original dossier to the personal data protection authority under the Ministry of Public Security within 60 days from the first data transfer date. The dossier must be updated when changes occur and kept available for inspections and assessments.
Which cases are exempt from preparing the impact assessment dossier?
Clause 6, Article 20 of Law 91/2025/QH15 exempts four groups: (1) competent state agencies transferring data; (2) organizations storing their own employees’ data on cloud computing services; (3) data subjects transferring their own data; (4) other cases as provided by the Government. Exemption from the dossier does not mean exemption from other data protection obligations.
What are the penalties for violating outbound data transfer rules?
Under Decree 330/2026/NĐ-CP (effective 19/8/2026): fines of VND 50–100 million for acts such as lacking binding responsibility documents, not securing data subject consent or not notifying data subjects, not applying security measures. For transferring data without an impact assessment dossier, misdeclaring data flows causing personal data leaks/loss, or continuing transfers after a stop order: fines of 1–5% of the preceding fiscal year’s revenue in the Vietnamese market depending on impact scale, up to 5% of the preceding year’s revenue.
How must employee/customer consent be expressed?
Under Article 9 of Law 91/2025/QH15, consent must be clear and specific for each purpose, printable and reproducible in writing — including in electronic form or a verifiable format. Silence or non-response does not count as consent. The law also provides cases where data may be processed without consent (emergencies, legal obligations, etc.) — each specific case should be cross-checked with counsel.
Useful links
You should talk to a lawyer if:
- Your company uses Google Workspace, Microsoft 365, AWS, or systems hosted abroad but has never prepared an impact assessment dossier.
- The parent company/group requires transferring HR or customer data abroad.
- Your company hires foreign partners to process data (outsourcing, analytics, customer care, etc.).
- There is no binding data protection responsibility document with the foreign recipient.
- You prepared dossiers under Decree 13/2023/NĐ-CP and need a review under Law 91/2025 and Decree 356/2025.
- You want to build internal personal data protection policies and incident response procedures for data leaks/loss.
Talk to a FLAT LAW FIRM lawyer
Send your current systems list and data transfer flows — we will inventory them, assess compliance gaps, and prepare a complete dossier under the new regulations.
Send a legal consultation requestImplementation time may vary by dossier, data flow scale, competent authority, and filing time. Website content is for general information only and does not substitute for legal advice on specific cases.
Laws, state agency jurisdiction, and administrative procedures may change over time, by locality, and by file. Please consult a lawyer before making decisions or transactions.