Personal Data Protection

Cross-Border Data Transfer Vietnam Under the 2025 Privacy Law

A focused guide to transferring personal data outside Vietnam under the evolving privacy framework. It explains how to map transfer routes, participants, purposes, safeguards, documentation and continuing oversight before information is made accessible from another jurisdiction.

JURION & PARTNERS 10 min read

Cross-border data transfer Vietnam compliance starts by identifying where data can be accessed, not only where a primary server sits. Cloud support, regional HR, group analytics, overseas security monitoring and vendor subprocessors can all create international flows. A defensible programme links each transfer to purpose, legal roles, current requirements, contractual controls and technical evidence.

Map cross-border data transfer Vietnam by real access

Inventory each process, system, dataset, individual group, destination, recipient, access method and onward recipient. Include remote administration, disaster recovery, email routing, collaboration tools, fraud systems and exports made by employees. Record whether data is stored abroad, viewed from abroad or routed through another country.

Validate interviews against architecture, cloud regions, contracts, integration lists, support logs and subprocessor disclosures. A vendor’s sales statement that data “remains local” may omit telemetry, tickets and emergency access.

Determine parties and purpose before choosing documents

Identify which organisation decides purposes and means and which processes on instructions under current law. Group companies do not become one legal actor simply because they share ownership. A regional team may be an independent recipient for one activity and a service provider for another.

Define a specific, necessary purpose. “Business operations” is too broad to test data minimisation, transparency, retention or onward use. If the overseas recipient wants its own analytics or product improvement, assess that additional purpose separately.

Use the 2025 law and 2025 decree, not a legacy checklist

Prepare a source register for Law 91/2025, Decree 356/2025 and other current data, cybersecurity and sector instruments. Record effective dates, filing or assessment duties, exceptions and authority guidance. Do not change only the citation on a Decree 13 template.

The legal team should state which current obligation applies to the exact transfer and which fact remains uncertain. Requirements can depend on data, parties, purpose, scale and sector. Keep official-source records with the decision file.

Transfer register fields
FieldControl questionEvidence
Purpose and dataIs the transfer necessary and limited?Process record and approved specification
Recipient and destinationWho obtains access and where?Architecture, entity and subprocessor list
Legal requirementWhich current rule and procedure apply?Official source and assessment record
Safeguards and lifecycleHow are access, retention and deletion controlled?Contract, settings, logs and deletion evidence

Build the required assessment from verified facts

Where current law requires an assessment, dossier, filing or update, populate it from the transfer register and evidence. Identify data categories, individuals, purpose, recipient, safeguards, risk, retention and incident process accurately. Assign an owner for submission and maintenance.

Cross-border data transfer Vietnam documentation is not static. New cloud regions, group restructures, subprocessors and product purposes may require update or reassessment. The change process should define triggers and legal review lead time.

Contract terms must match technical reality

Address documented purpose, role, confidentiality, security, location, subprocessing, rights requests, incident cooperation, authority support, audit evidence, retention, deletion and termination. Require advance information about material changes and a workable objection or exit process, with responsibility assigned for reviewing each notice.

Contract labels cannot override actual conduct. If a provider uses data for independent purposes or cannot delete it as promised, revise the architecture, purpose or agreement. Procurement should retain negotiated exceptions and risk acceptance.

Cloud governance includes support and metadata

Record primary region, backups, failover, support access, security telemetry, account metadata and content-delivery components. Test tenant settings and privileged access. Vendor documentation should be versioned because service architecture changes, and the legal register should identify which version supported approval.

Advisers test the client brief against contracts, registers and supporting papers for cross-border data transfer Vietnam
Advisers test the client brief against contracts, registers and supporting papers in the practical cross-border data transfer Vietnam workflow.

Use encryption, key management, segregation, logging and least privilege appropriate to risk. Local encryption is not a complete safeguard if an overseas operator can access decrypted content or keys.

Group transfers need the same discipline

Map each group entity, service and access population. Intercompany agreements should define purpose, role, rights, security, incident and deletion. Corporate policies can supplement but not replace the transfer record and applicable procedure, and group ownership does not remove entity-level accountability.

Regional HR, finance and compliance systems often combine employee and customer data. Restrict fields and roles to what each team needs. A group analytics project should not automatically inherit every locally collected dataset.

A transfer programme is credible when legal records and system evidence tell the same story: the organisation knows which data leaves Vietnam, who can use it, why the transfer is necessary, how onward access is controlled and when every copy must be deleted.

Jurion & Partners transfer-governance principle

Transparency and rights must work across systems

Notices should accurately describe overseas recipients or categories, purpose and other information required by current law. Consent, where applicable, needs a valid collection and withdrawal process; it should not be used to disguise unnecessary transfer.

Rights procedures must reach overseas systems and processors. Contracts and architecture should support search, correction, restriction or deletion as required. Test the process with a realistic request instead of assuming a vendor ticket is sufficient.

Incident response must cross organisational boundaries

Define notification from recipient to exporter, minimum facts, forensic preservation, containment authority, communication and regulator support. The contractual clock should give the Vietnamese organisation enough time to assess its own current duties and obtain evolving facts before applicable reporting deadlines.

Exercise scenarios involving an overseas subprocessor or regional administrator. Maintain a decision log of facts, legal analysis, notifications and remediation. Do not wait for the vendor’s final report before escalating a potentially material event.

Retention, deletion and exit need testable evidence

Set retention by purpose and legal requirement. Define deletion from active systems, replicas and routine backups, with practical backup exceptions documented. The exporter should receive confirmation appropriate to risk and retain evidence that downstream processors completed the required action.

Plan vendor exit before onboarding. Specify export format, transition access, deletion, subprocessor cascade and closure evidence. If the service cannot separate one customer’s data, that limitation belongs in the risk decision.

Transactions and new products trigger reassessment

M&A, restructuring, cloud migration and AI deployment can introduce new recipients and purposes. Due diligence should identify transfer records, filings, vendor terms, incidents and deletion capability. Restrict post-closing access until roles and procedures are confirmed.

Lawyer and decision-makers evaluate options around the working file for cross-border data transfer Vietnam
Lawyer and decision-makers evaluate options around the working file in the practical cross-border data transfer Vietnam workflow.

Product review should catch new SDKs, analytics, support locations and model training. A feature flag does not remove legal impact if production data already flows during testing.

Classify transfer risk by impact and control

A cross-border data transfer Vietnam review should distinguish ordinary business contact data from sensitive personal data, large-scale behavioural datasets, children’s information, biometrics, health, financial or employee-monitoring records. Classification should affect approval level, due diligence, access, encryption, testing and monitoring.

Risk is not determined by volume alone. A small dataset can create serious harm if it enables identity abuse, discrimination or exposure of confidential circumstances. Conversely, a large pseudonymised operational dataset may present a different profile, but pseudonymisation is not automatically anonymisation. Record re-identification possibilities and available additional information.

Use a decision matrix that states impact, likelihood, safeguards, residual risk, approver and review date. Exceptions should expire and require remediation. This gives management a consistent basis for comparing cloud, group and vendor transfers.

Vendor diligence should test capability, not collect certificates

Review the provider’s architecture, legal entities, subprocessor governance, access administration, encryption, incident history, continuity, deletion and audit evidence. Certifications can support diligence but do not answer whether the contracted configuration meets the organisation’s specific transfer requirement.

Ask how the provider identifies government or third-party requests, handles conflicts and notifies the customer where law permits. Determine whether customer data is used for service improvement or model training. A cross-border data transfer Vietnam contract should prohibit or control uses that are outside the approved purpose.

For critical services, assess concentration and exit feasibility. Test data export, restoration and deletion rather than relying only on contractual rights. Procurement should track renewal dates so legal changes and subprocessor updates can be reviewed before automatic renewal.

Remote work and support access require identity-level controls

International access may occur without copying a database. Regional engineers, travelling staff and overseas group managers can view or export records through ordinary tools. Create role-based access that limits fields, environments and duration, with privileged access approved and logged.

Use managed devices, strong authentication, session controls and restrictions on local download appropriate to risk. Review dormant accounts and emergency access. Support tickets should minimise included personal data and avoid attaching full production extracts where targeted examples suffice.

Cross-border data transfer Vietnam governance should connect HR joiner, mover and leaver events to application access. A contract restriction is ineffective if an overseas former contractor retains credentials after assignment end.

Localisation and transfer are related but different questions

A requirement to store specified data or maintain a presence in Vietnam does not necessarily answer whether overseas access is permitted, and a lawful transfer process does not eliminate a separate localisation duty. Identify the applicable cybersecurity, sector and data-law obligations for the actual service.

Architecture diagrams should show local and overseas components, primary and backup copies, access routes and system ownership. If local storage is required, verify operation and evidence rather than relying on the vendor’s region label. If a copy moves abroad, assess the transfer independently.

The cross-border data transfer Vietnam decision record should state both conclusions and their sources. This prevents one approval from being presented internally as resolving every data-location issue.

Maintain governance metrics that reveal drift

Track registered transfers, unapproved destinations, overdue assessments, subprocessor changes, privileged access, deletion exceptions, incidents, rights-request failures and vendor remediation. Metrics should identify owner and trend. A zero-exception report may indicate poor discovery rather than strong control.

Lawyers and management review the risk matrix before approving action for cross-border data transfer Vietnam
Lawyers and management review the risk matrix before approving action in the practical cross-border data transfer Vietnam workflow.

Sample technical logs against the legal register. Select several transfers and verify recipient, purpose, configuration, contract and retention. Internal audit should test whether product and procurement change gates detect new flows before launch.

Report material residual risk to the authorised management body. Cross-border data transfer Vietnam compliance remains a lifecycle obligation because vendors, architecture and law change after the initial assessment.

A practical cross-border data transfer Vietnam workflow

Legal services should connect transfer requirements with architecture, procurement and ongoing change control. The approved record should state assumptions, technical owner, legal owner, residual risk and the events requiring reassessment throughout the service lifecycle. A practical sequence is:

  1. Map all storage, access, routing and onward recipients.
  2. Define parties, purpose, necessity and data minimisation.
  3. Apply Law 91/2025 and Decree 356/2025 to the facts.
  4. Complete required assessments, records or procedures.
  5. Align contract, notice and technical safeguards.
  6. Test rights, incident, retention and deletion operation.
  7. Monitor vendors, regions and product changes.
  8. Retain official sources and evidence for review.

Questions before approving a transfer

Management should receive an answer grounded in the actual service and current law, not a vendor certification alone. Ask which data and purpose are essential, which overseas actors have access, which procedure applies, and what happens when the relationship ends.

Which official sources govern the decision date?

The file should retain the official records for Law 91/2025 and Decree 356/2025, the relevant effective dates and any sector instrument actually applied. It should also record that Decree 13/2023 ceased to have effect on 1 January 2026, preventing a legacy transfer pack from being mistaken for the operative framework.

Can the organisation prove the technical facts?

Require an architecture owner to confirm destinations, access, backups, keys and deletion. Legal conclusions should state assumptions and require reassessment if vendor documentation or configuration changes.

Conclusion: cross-border data transfer Vietnam needs evidence

Cross-border data transfer Vietnam compliance should produce a verified map, current-law record, aligned contracts and technical proof. Businesses may review Jurion & Partners’ Personal Data Protection practice, Book a Consultation, or Contact Jurion & Partners with their architecture, vendor list and transfer purpose.

This cross-border data transfer Vietnam article is general information current to its publication date. It is not a transfer assessment, filing determination, security review or sector-specific legal opinion.

Article topics
Article author

JURION & PARTNERS

Editorial Team · Jurion & Partners

Read more

Related Legal Insights

Tham khảo các bài viết liên quan để hiểu rõ hơn bối cảnh pháp lý, những tài liệu nên chuẩn bị và các điểm cần kiểm tra trước khi doanh nghiệp hoặc cá nhân đưa ra quyết định tiếp theo.

Prioritize an appointment

Do you want to talk directly with a lawyer?

Schedule an appointment so the Jurion & Partners team can understand your circumstances, identify the key legal questions, assess the available information and prepare an appropriate consultation approach aligned with your immediate priorities and practical objectives.

Schedule a consultation