Vietnam's data protection regime is no longer a decree-level framework that can be handled with a policy update. Law No. 91/2025/QH15 on Personal Data Protection was enacted on June 26, 2025, and took effect on January 1, 2026, elevating the regime from decree-level provisions to statutory law. Decree No. 356/2025/ND-CP was promulgated on December 31, 2025, as the guiding decree, took effect on the same date, and formally replaced Decree No. 13/2023/ND-CP.
For foreign-invested companies, the decisions that follow are structural, not administrative. They touch where your data sits, which entity in your group signs what, whether your regional shared-service centre is now a data processor, and who inside your Vietnam entity carries personal liability for a filing. Most companies that are already established, hiring, or restructuring in Vietnam are past the point of asking whether the law applies. They are asking which compliance model to build, and how much of it can be outsourced.
Does Vietnam's PDPL apply if your company is not incorporated in Vietnam?
Often, yes, and this is the point at which most overseas headquarters discover they are in scope.
The law applies to Vietnamese organisations and individuals, foreign entities operating in Vietnam, and foreign entities directly involved in processing personal data of Vietnamese citizens or eligible persons of Vietnamese origin residing in Vietnam. Compliance obligations can therefore extend to overseas headquarters, regional shared-service centres, cloud service providers, and software vendors that access, store, transfer, or process Vietnam-related personal data.
Two consequences matter commercially:
- A group structure is not a shield. There is no blanket exemption for intra-group transfers. An overseas parent and its Vietnam subsidiary are treated as separate legal entities and need a lawful basis for any access to or transfer of personal data. Routine access by a regional HR system or a global CRM can trigger obligations.
- "Processing" is deliberately broad. It covers collection, analysis, aggregation, encryption, modification, deletion, provision, disclosure, and transfer, an open-ended definition under which almost any activity touching personal data falls within scope.

What are your realistic compliance options?
There is no single compliant structure. In practice, foreign-invested companies in Vietnam are choosing between three models, and the right one depends on headcount, data volume, and whether Vietnam is a standalone market or one node in a regional data architecture.
|
Model |
Best suited to |
Key advantage |
Main trade-off |
|
Fully in-house, internal Data Protection Department, Vietnam-based DPO on payroll |
Entities processing sensitive data at scale, or regulated sectors (finance, insurance, health) |
Direct control; strongest position in an A05 inspection |
Highest fixed cost; hard to recruit qualified personnel locally |
|
Hybrid, internal owner for day-to-day, external adviser for filings and assessments |
Most mid-sized manufacturing, trading, and services FIEs |
Cost-efficient; keeps institutional knowledge internal |
Requires disciplined internal handover; accountability can blur |
|
Fully outsourced, external personal data protection service provider |
Newly established entities, representative offices, lean back-office operations |
Fast to stand up; qualification requirement met by the provider |
Provider capacity must be verified; you remain the accountable party |
Whichever model you choose, the appointment must be documented. Agencies and organisations must establish an internal Data Protection Department and/or appoint a DPO with adequate capacity or engage an external service provider. The appointment must take the form of a written decision, a board resolution or a letter signed by the legal representative and affixed with the company stamp, and a copy must be submitted alongside the DPIA and TIA dossiers. Where an external DPO is engaged, the service contract must be submitted too.
This is a genuine change from the previous regime. Under Decree 13, the requirement applied only to organisations processing sensitive personal data and imposed no qualification requirements on the appointed person. Decree 356 now sets specific qualifications for anyone appointed as DPO or as a member of the Data Protection Department. For SMEs without a privacy function, that is a new and non-trivial cost line.
Do the small-business exemptions apply to your business?
They are narrower than they look. Small enterprises and startups may postpone DPIA, TIA, and DPO obligations for up to five years from the law's effective date, and household businesses and micro-enterprises may be exempt from certain obligations, but these exemptions generally do not apply to organisations that provide personal data processing services, directly process sensitive personal data, or process personal data relating to 100,000 or more data subjects. Exempt entities must still obtain valid consent, implement security measures, and honour data subject rights.
A 40-person FIE running a consumer app or a recruitment platform will usually fail at least one of those tests.
Why is cross-border transfer the highest-risk area for foreign investors?
Because it carries the heaviest penalty exposure, and because the trigger is broader than most groups assume.
Decree 356 treats the following as cross-border transfers: storing personal data collected in Vietnam on server systems located outside Vietnam or on cloud services provided by foreign providers; transferring personal data from Vietnam to recipients located overseas; and processing personal data collected in Vietnam on platforms outside Vietnam.
That captures the standard multinational setup, a Vietnam entity feeding data into a Singapore or EU-hosted ERP, HRIS, or customer platform.
Which transfers require a TIA, and which are exempt?
Transferors must prepare and submit a Cross-border Transfer Impact Assessment to the MPS unless an exemption applies. Exemptions include transfers by competent state authorities, organisations storing their employees' personal data on cloud computing services, data subjects transferring their own data, journalism and media activities, publicly disclosed data, emergency situations, cross-border personnel management carried out under labour rules and internal regulations, and transfers made to conclude contracts or complete procedures relating to cross-border transport, logistics, remittance, payment, hotel bookings, visa applications, or scholarship applications.
The personnel-management exemptions are commercially significant and frequently overlooked, but they are conditional on the underlying labour documentation being in place, which is exactly where lean HR functions tend to be weak.
Filing mechanics to plan around:
|
Step |
Requirement |
|
Initial filing |
One original copy of the TIA to A05 within 60 days from the date of transfer |
|
Appraisal |
A05 reviews within 15 days and may require revision |
|
Revision window |
30 days to submit an updated dossier; missing this can attract administrative sanctions |
|
Ongoing |
Review and update every six months, or within 10 days of a material change |
|
DPIA equivalent |
Original copy to A05 within 60 days from the date processing begins |
A separate transfer agreement is also mandatory. It must specify the purpose, method, and scope of export, the recipient's processing purpose and method, storage location and duration, treatment of data after expiry, restrictions on onward disclosure to third parties, the recipient's protection measures, remedies and liability for breach, and the responsibilities of each party.
What do foreign companies most often get wrong?
Five recurring gaps, drawn from how the regime is being implemented:
- Assuming Decree 13 filings carry over unchanged. DPIA and TIA dossiers received by the authority before January 1, 2026, remain valid and do not need to be re-prepared, but any update made after that date must comply with the PDPL and Decree 356. In practice, the first six-month review is where the old dossier fails.
- Treating employee data as low risk. Employment is an explicitly regulated context, and HR systems are usually the first cross-border flow a Vietnam entity creates.
- Missing the vendor certification question. Organisations providing personal data processing as a business activity may need a Certificate of Eligibility for Personal Data Processing Service Business from the MPS, a due diligence point when selecting local payroll, IT, or marketing vendors.
- Underestimating the breach clock. Certain violations must be notified to the specialised authority within 72 hours of detection, a timeframe that is difficult to meet without a pre-built incident procedure.
- Overlooking parallel obligations. The Data Law imposes a separate transfer assessment for "important" and "core" data, which includes basic data on 100,000 or more Vietnamese citizens and sensitive data on 10,000 or more, and Decree 356 adds specific requirements for AI systems, blockchain, and cloud environments, including encryption at rest and in transit and annual compliance assessments.
What does non-compliance cost?
Violations involving the purchase or sale of personal data can attract fines of up to 10 times the unlawful revenue generated; unlawful cross-border transfers up to 5 percent of the enterprise's preceding year's revenue; and other violations up to VND 3 billion.
Worked example. A foreign-owned subsidiary recording USD 20 million (roughly VND 520 billion) in prior-year revenue that transfers Vietnamese customer data to a group platform without a filed TIA faces a theoretical ceiling of approximately VND 26 billion, around USD 1 million. That is materially larger than the VND 3 billion cap that applies to most other breaches.
One important qualifier: implementing these fines requires a dedicated decree on sanctioning, which the MPS has been preparing, and which had not been promulgated at the time of writing. Further enforcement guidance is expected through that forthcoming decree. The statutory ceilings are set; the mechanism is not yet complete. Companies treating that gap as breathing room should note that the MPS is launching a National Portal for Personal Data Protection to receive impact assessment filings and violation reports, which is expected to make companies considerably more exposed to complaints from employees and customers.
Where does local advisory support change the outcome?
Four areas where distance from Hanoi is a real disadvantage:
- Dossier drafting in Vietnamese to statutory templates. DPIA and TIA filings follow prescribed forms and are appraised by A05. Translation-quality drafting is a common cause of revision requests.
- Data mapping across a group. Establishing which entity is controller, processor, or controller-processor is a legal characterisation exercise with direct filing consequences.
- Employment-side compliance. Consent, internal labour regulations, and cross-border personnel data handling need to be aligned, otherwise the personnel-management exemption is unavailable.
- Technical remediation. Encryption, access control, and cloud configuration must match what the dossier claims.
What should your company do in the next 90 days?
|
Timeline |
Action |
|
Days 1–30 |
Map every personal data flow touching Vietnam, including group access. Classify basic vs sensitive data. Confirm controller/processor roles per entity. |
|
Days 31–60 |
Decide the operating model. Issue the DPO or DPD appointment decision or execute an external provider contract. Review consent mechanisms and privacy notices. |
|
Days 61–90 |
Prepare and file DPIA and, where applicable, TIA dossiers. Execute compliant intra-group data processing and transfer agreements. Stand up a 72-hour breach response procedure. |
|
Ongoing |
Six-monthly dossier review; 10-day update trigger on material change; annual assessment where AI, blockchain, or cloud systems are in use. |
Vietnam remains one of Asia's strongest destinations for manufacturing and services investment. The data regime does not change that calculus, but it does change what a properly structured entry or restructuring looks like.






