Skip to the content
Global Data RulesData governance rules, country by country

Vietnam

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Vietnam, but the police have to be able to see the paperwork. Anyone sending Vietnamese people's data abroad must build a transfer impact file, lodge it with the Ministry of Public Security and keep it ready for inspection. The ministry can order the flow to stop. Getting cross-border transfers wrong can cost 5 percent of last year's revenue.

Data governance in Vietnam

The eight things that decide how you handle data about people in Vietnam. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach a foreign company with no office in Vietnam, as long as it processes Vietnamese people's data or is involved in data processing that happens in Vietnam. There is no size or revenue floor to duck under. And if your business is processing personal data as a service for others, you cannot do it from abroad at all: that business must be a Vietnamese company, run by a Vietnamese citizen who lives in Vietnam.

Medium confidenceNational rulesRegister or notifyAppoint a data protection officer

Where the data is allowed to live

Yes, with paperwork. Vietnam does not publish a list of banned or approved countries. Instead, every transfer of a Vietnamese person's data abroad has to be backed by a written transfer impact file that goes to the cyber police, who can inspect it and can order you to stop sending data. On top of that, three areas are much tighter: online services the police ministry names can be told to keep data inside the country, state-classified 'core' and 'important' data carries extra control, and health bodies are simply barred from handing patient data to insurers without the patient asking in writing.

Medium confidenceYes, with paperworkApproval each timeSecurity review needed

Sending data out of the country

Build a file, send it to the cyber police, and keep it current. The file has to name both ends of the transfer, explain why the data is going abroad, list what is going, describe the protections, record the person's consent and attach a binding document between sender and receiver. One original copy goes to the cyber police within 60 days of starting to process the data. There is no approved-country list and no standard contract to sign, so nothing releases you from the file.

Medium confidenceApproval each timeSecurity review neededPut a transfer safeguard in place

The regulator, and whether it actually acts

The police. Data protection in Vietnam sits inside the Ministry of Public Security, and the working unit is its cyber security and high-tech crime department, known as A05. It is real, staffed and busy: in the first six months of 2025 alone it dealt with 56 cases of illegal trading in personal data covering more than 110 million records. What it does not yet have is the rulebook for fining ordinary companies under the new law. That decree was still a draft in May 2026, so the headline penalties are not yet routine practice.

Medium confidenceWaking up

How long you must keep it — and when to delete it

The ceiling is clear, the floor is not. When an employment contract ends, the employer must erase or destroy the worker's personal data unless the law or the contract says otherwise. Processing must also stop when the person who gave consent for a child's data takes that consent back. In the other direction, we could not verify Vietnam's minimum keeping periods for tax, accounting or security logs against an official source during this run, so treat those as unchecked rather than as absent.

Medium confidenceDelete data after a periodLet people delete their data

If something goes wrong

The clock most people quote is 72 hours to the cyber police, counted from the breach. If you are late you must also explain why you were late. A supplier who spots a breach must tell the company that hired it as fast as it can. Banks and credit businesses have a second duty: tell the customer when their bank, finance or credit information has leaked. Watch this answer: the 72-hour rule comes from the 2023 decree, and we could not confirm the deadline written into the 2025 decree that now sits under the new law.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend. One: selling personal data is banned outright, and the fine is up to ten times whatever you made from it. Two: the cross-border fine is a share of turnover, not a cash cap, so it scales with the size of the group. Three: the police can order you to stop sending data abroad simply because Vietnamese people's data has leaked, with no court in the way. Four: if you process personal data as a service for other companies, you need a police certificate, a Vietnamese company, a Vietnamese boss who lives in Vietnam and three qualified staff. Five: publishing anything about a child's private life needs the child's own agreement from age seven, on top of the parent's.

High confidencePercentage of global turnoverCriminal liabilityGet a parent's consent for childrenRegister or notifyAppoint a data protection officer

What's changing next

The next twelve months are about decrees, not new laws. A rewritten Cybersecurity Law took effect on 1 July 2026, and the government told the police ministry to have the decrees under it ready before that date. At least one of them, the decree that sets the actual fines for cyber security and personal data breaches, was still a draft in May 2026. A list of information systems treated as critical to national security is due before 31 December 2026. The new e-commerce law also started on 1 July 2026.

Medium confidenceIn forceProposed

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Luat Bao ve du lieu ca nhan - bao ve du lieu suc khoe va kinh doanh bao hiem

Act of parliament · Law No. 91/2025/QH15

In forceYes, with paperwork

A genuine sector wall. Health organisations may not hand patient data to other care providers or to health and life insurers unless the patient asks in writing, and any transfer to a reinsurance partner has to be written into the customer's own contract.

In force since 1 January 2026

Enforced by Ministry of Public Security

Transfer model: Approval each time · Accepted routes: Security review needed, Explicit consent

High confidence
Banking

Luat Bao ve du lieu ca nhan - hoat dong tai chinh, ngan hang, thong tin tin dung

Act of parliament · Law No. 91/2025/QH15

In forceYes, with paperwork

Banks, finance companies and credit bureaus must collect only what the credit-information job needs, may not score or rank a person without consent, and must tell the customer when their banking or credit information leaks.

In force since 1 January 2026

Enforced by State Bank of Vietnam

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Luat Bao ve du lieu ca nhan

Act of parliament · Law No. 91/2025/QH15

In forceYes, with paperwork

Vietnam's general privacy law, in force since 1 January 2026. It bans the sale of personal data outright, ties cross-border transfers to a filed impact assessment, and sets penalties as a share of turnover rather than a cash cap.

In force since 1 January 2026

Enforced by Ministry of Public Security

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

Nghi dinh quy dinh chi tiet mot so dieu va bien phap thi hanh Luat Bao ve du lieu ca nhan

Directly binding regulation · Decree No. 356/2025/ND-CP

In forceYes, with paperwork

The decree that puts flesh on the 2025 law. Its sharpest edge is a licensing regime: sell personal-data processing as a service in Vietnam and you need a Vietnamese company, a Vietnamese resident in charge, three qualified staff and a police certificate.

Enforced by Ministry of Public Security

Transfer model: Approval each time · Accepted routes: Security review needed

Medium confidence

Nghi dinh Bao ve du lieu ca nhan

Directly binding regulation · Decree No. 13/2023/ND-CP, articles 23 to 25

Partly in forceYes, with paperwork

The working mechanics of cross-border transfer and breach reporting: a file lodged with the cyber police within 60 days, 72 hours to report a breach, an annual inspection right, and a standing power to switch a data flow off.

In force since 1 July 2023

Enforced by Department of Cyber Security and High-Tech Crime Prevention (A05)

Transfer model: Approval each time · Accepted routes: Security review needed

Medium confidence

Who you would hear from

  • Bo Cong an

    Personal data protection, cyber security, the Law on Data, the core and important data lists, and the National Data Centre

    The ministry drafts the rules, licenses personal-data-processing service businesses and investigates data crime. It is the single most important body in Vietnamese data governance.

  • Cuc An ninh mang va phong, chong toi pham su dung cong nghe cao

    Receives breach reports and transfer impact files, inspects cross-border transfers, issues and revokes data-processing service certificates

    Actively working: 56 illegal personal-data trading cases covering more than 110 million records in the first half of 2025. But the decree that would let it fine ordinary companies under the 2025 law was still a draft in May 2026.

  • Chinh phu nuoc Cong hoa xa hoi chu nghia Viet Nam

    Issues the decrees that carry the operative detail of every data law

  • Ngan hang Nha nuoc Viet Nam

    Banking, payments and credit information supervision

    Operational as a prudential and payments regulator. We did not verify any banking-specific data localisation rule from its own site during this run.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact cross-border transfer procedure and deadlines under Decree 356/2025/ND-CP

    The signed copy published by the Government Portal is a scanned image, and no government site we could reach carries the decree as searchable text. The 60-day filing clock and the 72-hour breach clock quoted in this record come from the 2023 decree, which the 2025 decree may have replaced in whole or in part.

  • Whether Decree 13/2023/ND-CP has been repealed by Decree 356/2025/ND-CP

    We could not open a repeal clause. The rule is therefore marked partly in force rather than in force or repealed.

  • What article 26 of the 2025 Law on Cybersecurity actually says about storing data in Vietnam and opening a local office

    The government's own implementation plan tasks the police ministry with a decree detailing article 26(3) - the article that carried the storage and local-office duty in the 2018 law - but we could not open the 2025 law's text on a government site to confirm the wording, and we could not confirm the decree has been issued.

  • Whether the administrative penalties decree for cyber security and personal data protection has been issued since May 2026

    It was described by the police as a draft on 16 May 2026 and we found no later government notice. This is the reason enforcement is rated waking rather than active.

  • Sector localisation rules in banking, payments, insurance, securities, telecoms, cloud, gambling and mapping

    The government news search returned nothing on these and the national legal database at vbpl.vn refused our requests. Absence of a finding here is a gap in this record, not evidence that no rule exists.

  • Minimum retention periods for tax, accounting, company and security-log records

    No official source verified during this run. Only the deletion side of retention is evidenced.

  • The precise age at which a person stops being a child for data purposes

    The 2025 law's children article was verified, including the rule that a child aged 7 or over must agree before private information is published, but the definition of a child is set elsewhere in Vietnamese law and we did not verify it here.

  • The statute number of the Law on Data

    The passing date of 30 November 2024 and the commencement date of 1 July 2025 are both confirmed by government sources, but the official law number was not shown on the pages we could reach.

30-day cadence. Several decrees under the 2025 Cybersecurity Law were due before 1 July 2026 and had not appeared when we checked, including the one that sets the fines and the one that details the storage-in-Vietnam power. Any of them can land without consultation and would change this record materially.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Vietnam versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.