Skip to the content
Global Data RulesData governance rules, country by country

Vietnam

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Vietnam — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

You can send data out of Vietnam, but the police must be able to see the paperwork. If you send Vietnamese people's data abroad, you must build a transfer impact file. You lodge it with the Ministry of Public Security and keep it ready for inspection. The ministry can order you to stop sending data. Getting cross-border transfers wrong can cost 5 percent of last year's revenue.

Data governance in Vietnam

The eight things that decide how you handle data about people in Vietnam. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules apply even if you have no office in Vietnam. They catch you if you handle Vietnamese people's data. They also catch you if you are involved in data work happening in Vietnam. There is no size or revenue floor to duck under. And if your business is handling personal data as a service for others, you cannot do it from abroad at all. That business must be a Vietnamese company, run by a Vietnamese citizen who lives in Vietnam.

Not fully verified — see “What we're not sure about” below.

Where the data is allowed to live

Yes, with paperwork. Vietnam publishes no list of banned or approved countries. Instead, every transfer of a Vietnamese person's data abroad needs a written transfer impact file. That file goes to the cyber police. They can inspect it and can order you to stop sending data. Three areas are much tighter. The police ministry can order named online services to keep data inside the country. State-classified 'core' and 'important' data carries extra control. And health bodies may not hand patient data to insurers unless the patient asks in writing.

Ways to send data out:
Security review needed

What to do: Get the paperwork for one of the routes below signed before any data leaves Vietnam.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Build a file, send it to the cyber police, and keep it current. The file must name both ends of the transfer and explain why the data is going abroad. It must list what is going and describe the protections. It must record the person's consent and attach a binding document between sender and receiver. One original copy goes to the cyber police within 60 days of starting to handle the data. There is no approved-country list and no standard contract to sign. Nothing releases you from the file.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Security review needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

Not fully verified — see “What we're not sure about” below.

The regulator, and whether it actually acts

The police enforce it. Data protection in Vietnam sits inside the Ministry of Public Security. The working unit is its cyber security and high-tech crime department, known as A05. It is real, staffed and busy. In the first six months of 2025 alone it dealt with 56 cases of illegal trading in personal data. Those cases covered more than 110 million records. What it does not yet have is the rulebook for fining ordinary companies under the new law. That decree was still a draft in May 2026. So the big penalties are not yet routine.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

The rule on deleting data is clear. The rule on keeping it is not. When an employment contract ends, the employer must erase or destroy the worker's personal data. The exception is where the law or the contract says otherwise. You must also stop using a child's data when the person who gave consent takes it back. In the other direction, we could not confirm Vietnam's minimum keeping periods for tax, accounting or security logs against an official source. Treat those as unchecked rather than absent.

What you have to do here:
Delete data after a period · Let people delete their data

What to do: Set an automatic deletion job so data does not sit past its deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

The deadline most people quote is 72 hours to the cyber police, counted from the breach. If you are late, you must also explain why. A supplier who spots a breach must tell the company that hired it as fast as it can. Banks and credit businesses have a second duty. They must tell the customer when their bank, finance or credit information has leaked. Watch this answer. The 72-hour rule comes from the 2023 decree. We could not confirm the deadline written into the 2025 decree that now sits under the new law.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things cost people their weekend. One: selling personal data is banned outright, and the fine is up to ten times whatever you made from it. Two: the cross-border fine is a share of turnover, not a cash cap. So it scales with the size of the group. Three: the police can order you to stop sending data abroad simply because Vietnamese people's data has leaked. No court stands in the way. Four: if you handle personal data as a service for other companies, you need four things. A police certificate, a Vietnamese company, a Vietnamese boss who lives in Vietnam, and three qualified staff. Five: publishing anything about a child's private life needs the child's own agreement from age seven, on top of the parent's.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Percentage of global turnover · Criminal liability

What's changing next

The next twelve months are about decrees, not new laws. A rewritten Cybersecurity Law took effect on 1 July 2026. The government told the police ministry to have the decrees under it ready before that date. At least one is still missing. That is the decree setting the actual fines for cyber security and personal data breaches. It was still a draft in May 2026. A list of information systems treated as critical to national security is due before 31 December 2026. The new e-commerce law also started on 1 July 2026.

What to do: Diarise 31 December 2026 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Insurance rules

Official name: Luat Bao ve du lieu ca nhan - bao ve du lieu suc khoe va kinh doanh bao hiem · Law No. 91/2025/QH15 · Act of parliament

In forceYes, with paperwork

This is a real barrier for one industry. Health organisations may not hand patient data to other care providers, or to health and life insurers, unless the patient asks in writing. Any transfer to a reinsurance partner must be written into the customer's own contract.

In force since 1 January 2026

Enforced by Ministry of Public Security

How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Explicit consent

Banking

Banking rules

Official name: Luat Bao ve du lieu ca nhan - hoat dong tai chinh, ngan hang, thong tin tin dung · Law No. 91/2025/QH15 · Act of parliament

In forceYes, with paperwork

Banks, finance companies and credit bureaus must collect only what the credit-information job needs. They may not score or rank a person without consent. And they must tell the customer when their banking or credit information leaks.

In force since 1 January 2026

Enforced by State Bank of Vietnam

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Rules for sending data abroad

Official name: Luat Bao ve du lieu ca nhan · Law No. 91/2025/QH15 · Act of parliament

In forceYes, with paperwork

This is Vietnam's general privacy law, in force since 1 January 2026. It bans the sale of personal data outright. It ties cross-border transfers to a filed impact assessment. And it sets penalties as a share of turnover rather than a cash cap.

In force since 1 January 2026

Enforced by Ministry of Public Security

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Data rules

Official name: Nghi dinh quy dinh chi tiet mot so dieu va bien phap thi hanh Luat Bao ve du lieu ca nhan · Decree No. 356/2025/ND-CP · Directly binding regulation

In forceYes, with paperwork

This decree puts flesh on the 2025 law. Its sharpest edge is licensing. If you sell personal-data handling as a service in Vietnam, you need four things. A Vietnamese company, someone living in Vietnam in charge, three qualified staff, and a police certificate.

Enforced by Ministry of Public Security

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Not fully verified — see “What we're not sure about” below.

Breach reporting rules

Official name: Nghi dinh Bao ve du lieu ca nhan · Decree No. 13/2023/ND-CP, articles 23 to 25 · Directly binding regulation

Partly in forceYes, with paperwork

These are the working mechanics of cross-border transfers and breach reporting. You lodge a file with the cyber police within 60 days. You have 72 hours to report a breach. The police can inspect once a year. And they hold a standing power to switch a data flow off.

In force since 1 July 2023

Enforced by Department of Cyber Security and High-Tech Crime Prevention (A05)

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Bo Cong an

    Personal data protection, cyber security, the Law on Data, the core and important data lists, and the National Data Centre

    The ministry drafts the rules. It licenses businesses that handle personal data as a service. It also investigates data crime. It is the single most important body in Vietnamese data governance.

  • Cuc An ninh mang va phong, chong toi pham su dung cong nghe cao

    Receives breach reports and transfer impact files, inspects cross-border transfers, issues and revokes data-processing service certificates

    Actively working. It handled 56 illegal personal-data trading cases covering more than 110 million records in the first half of 2025. But the decree that would let it fine ordinary companies under the 2025 law was still a draft in May 2026.

  • Chinh phu nuoc Cong hoa xa hoi chu nghia Viet Nam

    Issues the decrees that carry the operative detail of every data law

  • Ngan hang Nha nuoc Viet Nam

    Banking, payments and credit information supervision

    Working as a prudential and payments regulator. We could not confirm any banking rule requiring data to stay in Vietnam from its own site.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact cross-border transfer procedure and deadlines under Decree 356/2025/ND-CP

    The signed copy published by the Government Portal is a scanned image. No government site we reached carries the decree as searchable text. The 60-day filing deadline and the 72-hour breach deadline in this record come from the 2023 decree. The 2025 decree may have replaced them in whole or in part.

  • Whether Decree 13/2023/ND-CP has been repealed by Decree 356/2025/ND-CP

    We could not find a clause repealing it. So we mark the rule partly in force, rather than in force or repealed.

  • What article 26 of the 2025 Law on Cybersecurity actually says about storing data in Vietnam and opening a local office

    The government's own implementation plan tells the police ministry to write a decree detailing article 26(3). That is the article that carried the storage and local-office duty in the 2018 law. We could not open the 2025 law's text on a government site to confirm the wording. We also could not confirm that the decree has been issued.

  • Whether the administrative penalties decree for cyber security and personal data protection has been issued since May 2026

    The police described it as a draft on 16 May 2026, and we found no later government notice. That is why we rate enforcement as waking rather than active.

  • Sector localisation rules in banking, payments, insurance, securities, telecoms, cloud, gambling and mapping

    The government news search returned nothing on these, and the national legal database at vbpl.vn refused our requests. We found no rule, but that is a gap in this record rather than proof that none exists. If you work in these industries, check before you rely on it.

  • Minimum retention periods for tax, accounting, company and security-log records

    We confirmed no official source for these. Only the deletion side of the retention rules is evidenced. Treat the minimum keeping periods as unchecked.

  • The precise age at which a person stops being a child for data purposes

    We confirmed the 2025 law's children article. That includes the rule that a child aged 7 or over must agree before private information is published. The definition of a child is set elsewhere in Vietnamese law, and we did not confirm it here.

  • The statute number of the Law on Data

    Government sources confirm the passing date of 30 November 2024 and the start date of 1 July 2025. The official law number was not shown on the pages we could reach.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.