Personal Data Protection
Cross-Border Data Transfer Vietnam Under the 2025 Privacy Law
A focused guide to transferring personal data outside Vietnam under the evolving privacy framework. It explains how to map transfer routes, participants, purposes, safeguards, documentation and continuing oversight before information is made accessible from another jurisdiction.
Cross-border data transfer Vietnam compliance starts by identifying where data can be accessed, not only where a primary server sits. Cloud support, regional HR, group analytics, overseas security monitoring and vendor subprocessors can all create international flows. A defensible programme links each transfer to purpose, legal roles, current requirements, contractual controls and technical evidence.
For August 2026, use Personal Data Protection Law No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, effective 1 January 2026. Decree No. 13/2023/ND-CP ceased to have effect on that date and is not current authority.
Map cross-border data transfer Vietnam by real access
Inventory each process, system, dataset, individual group, destination, recipient, access method and onward recipient. Include remote administration, disaster recovery, email routing, collaboration tools, fraud systems and exports made by employees. Record whether data is stored abroad, viewed from abroad or routed through another country.
Validate interviews against architecture, cloud regions, contracts, integration lists, support logs and subprocessor disclosures. A vendor’s sales statement that data “remains local” may omit telemetry, tickets and emergency access.
Determine parties and purpose before choosing documents
Identify which organisation decides purposes and means and which processes on instructions under current law. Group companies do not become one legal actor simply because they share ownership. A regional team may be an independent recipient for one activity and a service provider for another.
Define a specific, necessary purpose. “Business operations” is too broad to test data minimisation, transparency, retention or onward use. If the overseas recipient wants its own analytics or product improvement, assess that additional purpose separately.
Use the 2025 law and 2025 decree, not a legacy checklist
Prepare a source register for Law 91/2025, Decree 356/2025 and other current data, cybersecurity and sector instruments. Record effective dates, filing or assessment duties, exceptions and authority guidance. Do not change only the citation on a Decree 13 template.
The legal team should state which current obligation applies to the exact transfer and which fact remains uncertain. Requirements can depend on data, parties, purpose, scale and sector. Keep official-source records with the decision file.
| Field | Control question | Evidence |
|---|---|---|
| Purpose and data | Is the transfer necessary and limited? | Process record and approved specification |
| Recipient and destination | Who obtains access and where? | Architecture, entity and subprocessor list |
| Legal requirement | Which current rule and procedure apply? | Official source and assessment record |
| Safeguards and lifecycle | How are access, retention and deletion controlled? | Contract, settings, logs and deletion evidence |
Build the required assessment from verified facts
Where current law requires an assessment, dossier, filing or update, populate it from the transfer register and evidence. Identify data categories, individuals, purpose, recipient, safeguards, risk, retention and incident process accurately. Assign an owner for submission and maintenance.
Cross-border data transfer Vietnam documentation is not static. New cloud regions, group restructures, subprocessors and product purposes may require update or reassessment. The change process should define triggers and legal review lead time.
Contract terms must match technical reality
Address documented purpose, role, confidentiality, security, location, subprocessing, rights requests, incident cooperation, authority support, audit evidence, retention, deletion and termination. Require advance information about material changes and a workable objection or exit process, with responsibility assigned for reviewing each notice.
Contract labels cannot override actual conduct. If a provider uses data for independent purposes or cannot delete it as promised, revise the architecture, purpose or agreement. Procurement should retain negotiated exceptions and risk acceptance.
Cloud governance includes support and metadata
Record primary region, backups, failover, support access, security telemetry, account metadata and content-delivery components. Test tenant settings and privileged access. Vendor documentation should be versioned because service architecture changes, and the legal register should identify which version supported approval.

Use encryption, key management, segregation, logging and least privilege appropriate to risk. Local encryption is not a complete safeguard if an overseas operator can access decrypted content or keys.
Group transfers need the same discipline
Map each group entity, service and access population. Intercompany agreements should define purpose, role, rights, security, incident and deletion. Corporate policies can supplement but not replace the transfer record and applicable procedure, and group ownership does not remove entity-level accountability.
Regional HR, finance and compliance systems often combine employee and customer data. Restrict fields and roles to what each team needs. A group analytics project should not automatically inherit every locally collected dataset.
A transfer programme is credible when legal records and system evidence tell the same story: the organisation knows which data leaves Vietnam, who can use it, why the transfer is necessary, how onward access is controlled and when every copy must be deleted.
Jurion & Partners transfer-governance principle
Transparency and rights must work across systems
Notices should accurately describe overseas recipients or categories, purpose and other information required by current law. Consent, where applicable, needs a valid collection and withdrawal process; it should not be used to disguise unnecessary transfer.
Rights procedures must reach overseas systems and processors. Contracts and architecture should support search, correction, restriction or deletion as required. Test the process with a realistic request instead of assuming a vendor ticket is sufficient.
Incident response must cross organisational boundaries
Define notification from recipient to exporter, minimum facts, forensic preservation, containment authority, communication and regulator support. The contractual clock should give the Vietnamese organisation enough time to assess its own current duties and obtain evolving facts before applicable reporting deadlines.
Exercise scenarios involving an overseas subprocessor or regional administrator. Maintain a decision log of facts, legal analysis, notifications and remediation. Do not wait for the vendor’s final report before escalating a potentially material event.
Do not approve a transfer based solely on contract promises while configuration permits unknown regions or unrestricted support access. Verify actual regions, identities, logs, backups and subprocessors before launch, at renewal and after every material service or architecture change.
Retention, deletion and exit need testable evidence
Set retention by purpose and legal requirement. Define deletion from active systems, replicas and routine backups, with practical backup exceptions documented. The exporter should receive confirmation appropriate to risk and retain evidence that downstream processors completed the required action.
Plan vendor exit before onboarding. Specify export format, transition access, deletion, subprocessor cascade and closure evidence. If the service cannot separate one customer’s data, that limitation belongs in the risk decision.
Transactions and new products trigger reassessment
M&A, restructuring, cloud migration and AI deployment can introduce new recipients and purposes. Due diligence should identify transfer records, filings, vendor terms, incidents and deletion capability. Restrict post-closing access until roles and procedures are confirmed.

Product review should catch new SDKs, analytics, support locations and model training. A feature flag does not remove legal impact if production data already flows during testing.
Classify transfer risk by impact and control
A cross-border data transfer Vietnam review should distinguish ordinary business contact data from sensitive personal data, large-scale behavioural datasets, children’s information, biometrics, health, financial or employee-monitoring records. Classification should affect approval level, due diligence, access, encryption, testing and monitoring.
Risk is not determined by volume alone. A small dataset can create serious harm if it enables identity abuse, discrimination or exposure of confidential circumstances. Conversely, a large pseudonymised operational dataset may present a different profile, but pseudonymisation is not automatically anonymisation. Record re-identification possibilities and available additional information.
Use a decision matrix that states impact, likelihood, safeguards, residual risk, approver and review date. Exceptions should expire and require remediation. This gives management a consistent basis for comparing cloud, group and vendor transfers.
Vendor diligence should test capability, not collect certificates
Review the provider’s architecture, legal entities, subprocessor governance, access administration, encryption, incident history, continuity, deletion and audit evidence. Certifications can support diligence but do not answer whether the contracted configuration meets the organisation’s specific transfer requirement.
Ask how the provider identifies government or third-party requests, handles conflicts and notifies the customer where law permits. Determine whether customer data is used for service improvement or model training. A cross-border data transfer Vietnam contract should prohibit or control uses that are outside the approved purpose.
For critical services, assess concentration and exit feasibility. Test data export, restoration and deletion rather than relying only on contractual rights. Procurement should track renewal dates so legal changes and subprocessor updates can be reviewed before automatic renewal.
Remote work and support access require identity-level controls
International access may occur without copying a database. Regional engineers, travelling staff and overseas group managers can view or export records through ordinary tools. Create role-based access that limits fields, environments and duration, with privileged access approved and logged.
Use managed devices, strong authentication, session controls and restrictions on local download appropriate to risk. Review dormant accounts and emergency access. Support tickets should minimise included personal data and avoid attaching full production extracts where targeted examples suffice.
Cross-border data transfer Vietnam governance should connect HR joiner, mover and leaver events to application access. A contract restriction is ineffective if an overseas former contractor retains credentials after assignment end.
Localisation and transfer are related but different questions
A requirement to store specified data or maintain a presence in Vietnam does not necessarily answer whether overseas access is permitted, and a lawful transfer process does not eliminate a separate localisation duty. Identify the applicable cybersecurity, sector and data-law obligations for the actual service.
Architecture diagrams should show local and overseas components, primary and backup copies, access routes and system ownership. If local storage is required, verify operation and evidence rather than relying on the vendor’s region label. If a copy moves abroad, assess the transfer independently.
The cross-border data transfer Vietnam decision record should state both conclusions and their sources. This prevents one approval from being presented internally as resolving every data-location issue.
Maintain governance metrics that reveal drift
Track registered transfers, unapproved destinations, overdue assessments, subprocessor changes, privileged access, deletion exceptions, incidents, rights-request failures and vendor remediation. Metrics should identify owner and trend. A zero-exception report may indicate poor discovery rather than strong control.

Sample technical logs against the legal register. Select several transfers and verify recipient, purpose, configuration, contract and retention. Internal audit should test whether product and procurement change gates detect new flows before launch.
Report material residual risk to the authorised management body. Cross-border data transfer Vietnam compliance remains a lifecycle obligation because vendors, architecture and law change after the initial assessment.
A practical cross-border data transfer Vietnam workflow
Legal services should connect transfer requirements with architecture, procurement and ongoing change control. The approved record should state assumptions, technical owner, legal owner, residual risk and the events requiring reassessment throughout the service lifecycle. A practical sequence is:
- Map all storage, access, routing and onward recipients.
- Define parties, purpose, necessity and data minimisation.
- Apply Law 91/2025 and Decree 356/2025 to the facts.
- Complete required assessments, records or procedures.
- Align contract, notice and technical safeguards.
- Test rights, incident, retention and deletion operation.
- Monitor vendors, regions and product changes.
- Retain official sources and evidence for review.
Questions before approving a transfer
Management should receive an answer grounded in the actual service and current law, not a vendor certification alone. Ask which data and purpose are essential, which overseas actors have access, which procedure applies, and what happens when the relationship ends.
Which official sources govern the decision date?
The file should retain the official records for Law 91/2025 and Decree 356/2025, the relevant effective dates and any sector instrument actually applied. It should also record that Decree 13/2023 ceased to have effect on 1 January 2026, preventing a legacy transfer pack from being mistaken for the operative framework.
Can the organisation prove the technical facts?
Require an architecture owner to confirm destinations, access, backups, keys and deletion. Legal conclusions should state assumptions and require reassessment if vendor documentation or configuration changes.
Conclusion: cross-border data transfer Vietnam needs evidence
Cross-border data transfer Vietnam compliance should produce a verified map, current-law record, aligned contracts and technical proof. Businesses may review Jurion & Partners’ Personal Data Protection practice, Book a Consultation, or Contact Jurion & Partners with their architecture, vendor list and transfer purpose.
This cross-border data transfer Vietnam article is general information current to its publication date. It is not a transfer assessment, filing determination, security review or sector-specific legal opinion.
Phân tích
Phân tích
Phân tích