Vietnam
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Vietnam — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Vietnam, but the police must be able to see the paperwork. If you send Vietnamese people's data abroad, you must build a transfer impact file. You lodge it with the Ministry of Public Security and keep it ready for inspection. The ministry can order you to stop sending data. Getting cross-border transfers wrong can cost 5 percent of last year's revenue.
Data governance in Vietnam
The eight things that decide how you handle data about people in Vietnam. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules apply even if you have no office in Vietnam. They catch you if you handle Vietnamese people's data. They also catch you if you are involved in data work happening in Vietnam. There is no size or revenue floor to duck under. And if your business is handling personal data as a service for others, you cannot do it from abroad at all. That business must be a Vietnamese company, run by a Vietnamese citizen who lives in Vietnam.
The 2023 personal data decree sets out its reach in four parts. It covers Vietnamese bodies, organisations and individuals. It covers foreign bodies, organisations and individuals in Vietnam. It covers Vietnamese bodies, organisations and individuals operating abroad. And it covers foreign bodies, organisations and individuals directly involved in data work in Vietnam. The 2025 Law on Personal Data Protection replaced the decree's parent law from 1 January 2026. Decree 356/2025 now carries the detail. We could not open the 2025 Law's own scope article on a government site. So the wording quoted here is the 2023 decree's. Decree 356/2025 adds a harder rule for one group. An organisation that sells personal-data handling services must be set up under Vietnamese law. Its head of data work must be a Vietnamese citizen living in Vietnam. And it must have at least three staff who meet the qualification test.
Sources
- Official sourceGovernment Portal of Viet Nam (Xay dung chinh sach)Full text of Decree 13/2023/ND-CP on personal data protection, article 1 (scope)
xaydungchinhsach.chinhphu.vn
“Nghi dinh nay ap dung doi voi: ... d) Co quan, to chuc, ca nhan nuoc ngoai truc tiep tham gia hoac co lien quan den hoat dong xu ly du lieu ca nhan tai Viet Nam.”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamConditions for organisations providing personal data processing services (Decree 356/2025/ND-CP of 31 December 2025)
baochinhphu.vn
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Vietnam publishes no list of banned or approved countries. Instead, every transfer of a Vietnamese person's data abroad needs a written transfer impact file. That file goes to the cyber police. They can inspect it and can order you to stop sending data. Three areas are much tighter. The police ministry can order named online services to keep data inside the country. State-classified 'core' and 'important' data carries extra control. And health bodies may not hand patient data to insurers unless the patient asks in writing.
- Ways to send data out:
- Security review needed
Industry by industry, checked on 18 August 2026. BANKING, CREDIT AND PAYMENTS. The 2025 Law adds duties for finance, banking and credit-information businesses. No credit scoring without consent. Collect only the minimum needed. Tell the customer when account or credit information leaks. We found no rule requiring banking data to stay in Vietnam in an official source. Treat that as unconfirmed, not as an absence. HEALTH AND INSURANCE. This is a real barrier. Health bodies may not pass personal data to other healthcare providers, health insurers or life insurers unless the person asks in writing. Reinsurance transfers must be spelled out in the customer's contract. TELECOMS, SOCIAL MEDIA, ONLINE PAYMENT, CLOUD AND GAMING. These are the services the cybersecurity rules aim their storage-in-Vietnam power at. The power works by order of the police ministry. It does not apply automatically. The decree setting out the detail under the 2025 Cybersecurity Law was still being written when we checked. GOVERNMENT AND STATE DATA. The Prime Minister has issued a list of 26 core data and 18 important data categories. Nearly all are non-public data held by state bodies. They include health data, geospatial and aerial imagery of sensitive sites, finance and budget data, and non-public data about organisations and citizens. E-COMMERCE. From 1 July 2026 a foreign platform does not have to set up a Vietnamese company. But it must appoint a Vietnamese legal entity to carry its duties. Sellers are identified through the national digital identity system. MAPPING, EDUCATION, DEFENCE AND GAMBLING. We confirmed no rule against an official source.
Sources
- Official sourceGovernment Portal of Viet NamFull text of Decree 13/2023/ND-CP, article 25 (transfer of personal data abroad)
xaydungchinhsach.chinhphu.vn
“Du lieu ca nhan cua cong dan Viet Nam duoc chuyen ra nuoc ngoai trong truong hop Ben chuyen du lieu ra nuoc ngoai lap Ho so danh gia tac dong chuyen du lieu ca nhan ra nuoc ngoai va thuc hien cac thu tuc theo quy dinh.”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamPrime Minister issues the list of core data and important data (Decision 20/2025/QD-TTg; criteria in Decree 165/2025/ND-CP of 30 June 2025)
baochinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment Portal of Viet NamHealth information and insurance business rules in the Law on Personal Data Protection No. 91/2025/QH15
xaydungchinhsach.chinhphu.vn
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Vietnam.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Build a file, send it to the cyber police, and keep it current. The file must name both ends of the transfer and explain why the data is going abroad. It must list what is going and describe the protections. It must record the person's consent and attach a binding document between sender and receiver. One original copy goes to the cyber police within 60 days of starting to handle the data. There is no approved-country list and no standard contract to sign. Nothing releases you from the file.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Security review needed
Vietnam has no list of countries at all, neither banned nor approved. You file paperwork and the police inspect it. They also hold a live power to stop a transfer. Under the 2023 decree the police may inspect a transfer once a year. They may inspect at any time after a leak or a suspected breach. They may order the transfer to stop in three cases. Where the data is used against Vietnam's national interests or security. Where the sender ignores a request to complete the file. Or simply where Vietnamese citizens' data has leaked. A sender has ten days to fix a file the police say is incomplete. Decree 356/2025 details the 2025 Law. It still turns on the same two documents: a data handling impact file and a cross-border transfer impact file. Passing both is a licensing condition for businesses that handle personal data as a service. We could not open the 2025 decree's own transfer article. So the 60-day and 10-day deadlines quoted here are the 2023 decree's, and you should re-check them.
Sources
- Official sourceGovernment Portal of Viet NamFull text of Decree 13/2023/ND-CP, article 25(3) and 25(8)
xaydungchinhsach.chinhphu.vn
“Ben chuyen du lieu ra nuoc ngoai gui 01 ban chinh ho so toi Bo Cong an (Cuc An ninh mang va phong, chong toi pham su dung cong nghe cao) ... trong thoi gian 60 ngay ke tu ngay tien hanh xu ly du lieu ca nhan.”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamDecree 356/2025/ND-CP - both impact files are a licensing condition for data-processing service businesses
baochinhphu.vn
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
Not fully verified — see “What we're not sure about” below.The regulator, and whether it actually acts
The police enforce it. Data protection in Vietnam sits inside the Ministry of Public Security. The working unit is its cyber security and high-tech crime department, known as A05. It is real, staffed and busy. In the first six months of 2025 alone it dealt with 56 cases of illegal trading in personal data. Those cases covered more than 110 million records. What it does not yet have is the rulebook for fining ordinary companies under the new law. That decree was still a draft in May 2026. So the big penalties are not yet routine.
A05 receives breach reports. It receives and assesses transfer impact files, and inspects transfers. Under Decree 356/2025 it issues, re-issues and revokes the certificates that personal-data service businesses must hold. The Ministry of Public Security also leads on the Law on Data, the National Data Centre, and the core and important data lists. That makes it unusually powerful next to a European-style privacy authority. The same ministry writes the rules, licenses the market and investigates crime. We rate it waking rather than active for two reasons. The penalties decree covering cyber security and personal data protection had not been issued when we checked. And we found no published register of company fines under the 2025 Law.
Sources
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamLaw on Personal Data Protection in force from 1 January 2026 - A05 casework figures for the first half of 2025
baochinhphu.vn
“chi trong 6 thang dau nam 2025, luc luong chuc nang da phat hien va xu ly 56 vu viec lien quan den mua ban trai phep du lieu ca nhan, voi quy mo hon 110 trieu ban ghi du lieu”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamDeputy Director of A05 on the draft decree on administrative penalties in cyber security and personal data protection, 16 May 2026
baochinhphu.vn
Link checked 18 August 2026
How long you must keep it — and when to delete it
The rule on deleting data is clear. The rule on keeping it is not. When an employment contract ends, the employer must erase or destroy the worker's personal data. The exception is where the law or the contract says otherwise. You must also stop using a child's data when the person who gave consent takes it back. In the other direction, we could not confirm Vietnam's minimum keeping periods for tax, accounting or security logs against an official source. Treat those as unchecked rather than absent.
- What you have to do here:
- Delete data after a period · Let people delete their data
The employment rule has three parts. Comply with the data law, labour law and the Law on Data. Keep the worker's personal data only for the period the law sets or the parties agreed. And erase or destroy it when the contract ends, unless an agreement or a legal rule says otherwise. Sometimes a duty to keep data under tax or accounting law clashes with that erasure duty. The erasure duty gives way, because it is written as subject to other law. So the industry rule usually decides the answer, not the data law.
Sources
- Official sourceGovernment Portal of Viet NamNotable provisions of the Law on Personal Data Protection 2025, including the duty to erase employee data when the contract ends
xaydungchinhsach.chinhphu.vn
“Phai xoa, huy du lieu ca nhan cua nguoi lao dong khi cham dut hop dong, tru truong hop theo thoa thuan hoac phap luat co quy dinh khac.”
Link checked 18 August 2026
- Official sourceGovernment Portal of Viet NamChildren and people lacking legal capacity under Law No. 91/2025/QH15 - processing must stop when consent is withdrawn
xaydungchinhsach.chinhphu.vn
Link checked 18 August 2026
What to do: Set an automatic deletion job so data does not sit past its deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
The deadline most people quote is 72 hours to the cyber police, counted from the breach. If you are late, you must also explain why. A supplier who spots a breach must tell the company that hired it as fast as it can. Banks and credit businesses have a second duty. They must tell the customer when their bank, finance or credit information has leaked. Watch this answer. The 72-hour rule comes from the 2023 decree. We could not confirm the deadline written into the 2025 decree that now sits under the new law.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 2023 decree also fixes what the notice must contain. That is the nature, time, place and actors of the breach. It is also the categories and volume of data involved. Plus contact details for the person responsible for data protection, the likely consequences, and the steps you took to limit harm. You may notify in stages where you do not yet know everything. You must also draw up a record of the incident and work with the cyber police on handling it. Separately, you must report to the cyber police when you discover unlawful acts against personal data. The same goes for using data outside the agreed purpose, or failing to honour a person's rights.
Sources
- Official sourceGovernment Portal of Viet NamFull text of Decree 13/2023/ND-CP, article 23 (notification of personal data protection breaches)
xaydungchinhsach.chinhphu.vn
“thong bao cho Bo Cong an (Cuc An ninh mang va phong, chong toi pham su dung cong nghe cao) cham nhat 72 gio sau khi xay ra hanh vi vi pham ... Truong hop thong bao sau 72 gio thi phai kem theo ly do thong bao cham, muon.”
Link checked 18 August 2026
- Official sourceGovernment Portal of Viet NamFinance, banking and credit information duties under Law No. 91/2025/QH15, including telling customers about leaks
xaydungchinhsach.chinhphu.vn
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things cost people their weekend. One: selling personal data is banned outright, and the fine is up to ten times whatever you made from it. Two: the cross-border fine is a share of turnover, not a cash cap. So it scales with the size of the group. Three: the police can order you to stop sending data abroad simply because Vietnamese people's data has leaked. No court stands in the way. Four: if you handle personal data as a service for other companies, you need four things. A police certificate, a Vietnamese company, a Vietnamese boss who lives in Vietnam, and three qualified staff. Five: publishing anything about a child's private life needs the child's own agreement from age seven, on top of the parent's.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Percentage of global turnover · Criminal liability
More detail on each. The list of banned acts in the 2025 Law has seven parts. It includes using data against the state, obstructing data protection work, unlawful data handling, buying or selling personal data, and taking or deliberately leaking data. Fines: up to ten times the gain for buying or selling data. Up to 5 percent of the organisation's previous year's revenue for breaking the cross-border transfer rules. Up to 3 billion Vietnamese dong, roughly 115,000 US dollars, for everything else. An individual pays half the maximum set for organisations. Criminal prosecution is still available. Social networks and online communication services carry their own list. They may not demand a photo or video of an identity document to verify an account. They must let users refuse cookie files. They must offer a do-not-track choice. And they may not listen to calls or read messages without consent. Location tracking through radio-frequency tags and similar technology is off. It is allowed only if the person agrees or an authority requires it. Mobile app platforms must offer location choices.
Sources
- Official sourceGovernment Portal of Viet NamProhibited acts and penalties under the Law on Personal Data Protection (articles 7 and 8)
xaydungchinhsach.chinhphu.vn
“Muc phat tien toi da trong xu phat vi pham hanh chinh doi voi to chuc co hanh vi vi pham quy dinh chuyen du lieu ca nhan xuyen bien gioi la 5% doanh thu cua nam truoc lien ke cua to chuc do.”
Link checked 18 August 2026
- Official sourceGovernment Portal of Viet NamLocation data and biometric data under Law No. 91/2025/QH15, article 31
xaydungchinhsach.chinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamDecree 356/2025/ND-CP - certificate, Vietnamese entity and staffing conditions for data processing services
baochinhphu.vn
Link checked 18 August 2026
What's changing next
The next twelve months are about decrees, not new laws. A rewritten Cybersecurity Law took effect on 1 July 2026. The government told the police ministry to have the decrees under it ready before that date. At least one is still missing. That is the decree setting the actual fines for cyber security and personal data breaches. It was still a draft in May 2026. A list of information systems treated as critical to national security is due before 31 December 2026. The new e-commerce law also started on 1 July 2026.
Dated items. 1 July 2026: Law on Cybersecurity No. 116/2025/QH15 takes effect. It merges the 2018 cybersecurity law and the 2015 network information security law into 8 chapters and 45 articles. 1 July 2026: Law on E-commerce No. 122/2025/QH15 takes effect. A foreign platform does not have to set up a Vietnamese company. But it must appoint a Vietnamese legal entity to carry its duties. Sellers are identified through the national digital identity system. Before 31 December 2026: the Prime Minister's list of information systems critical to national security. Pending with no fixed date: the penalties decree for cyber security and personal data protection. It will also cover artificial-intelligence and deepfake content, and platform duties. Also pending: a decree on preventing and handling unlawful information. That would regulate social media group administrators. It would also push identity checks for social accounts, bank accounts and phone numbers. POWERS ALREADY HELD, all usable without new legislation. The police ministry can order data storage in Vietnam and a local office for named services. The Prime Minister can amend the core and important data lists by decision. And there is a standing power to order a company to stop transferring data abroad.
Sources
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamPlan for implementing the Law on Cybersecurity No. 116/2025/QH15 - decrees due before 1 July 2026, critical systems list before 31 December 2026
baochinhphu.vn
“Luat An ninh mang so 116/2025/QH15 ... co hieu luc thi hanh tu ngay 01/7/2026.”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamPlan for implementing the Law on E-commerce No. 122/2025/QH15, effective 1 July 2026
baochinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamDraft decrees under the 2025 Cybersecurity Law, 16 May 2026
baochinhphu.vn
Link checked 18 August 2026
What to do: Diarise 31 December 2026 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Insurance rules
Official name: Luat Bao ve du lieu ca nhan - bao ve du lieu suc khoe va kinh doanh bao hiem · Law No. 91/2025/QH15 · Act of parliament
This is a real barrier for one industry. Health organisations may not hand patient data to other care providers, or to health and life insurers, unless the patient asks in writing. Any transfer to a reinsurance partner must be written into the customer's own contract.
Enforced by Ministry of Public Security
How this country controls where data goes: Approval each time · Accepted routes: Security review needed, Explicit consent
What you have to do
- Get consentYou need consent to collect and use health data, outside the narrow exceptions the law sets.
- Extra vendor secrecy termsHealth bodies must not pass personal data to third-party healthcare providers, health insurers or life insurers unless the person asks in writing.
- Written vendor contractWhere a reinsurer or retrocession partner will receive customer data, that must be stated in the customer's contract.
Sources
- Official sourceGovernment Portal of Viet NamPersonal data protection for health information and insurance business under Law No. 91/2025/QH15
xaydungchinhsach.chinhphu.vn
“khong cung cap du lieu ca nhan cho ben thu ba la to chuc cung cap dich vu cham soc suc khoe hoac dich vu bao hiem suc khoe, bao hiem nhan tho, tru truong hop co yeu cau bang van ban cua chu the du lieu ca nhan”
Link checked 18 August 2026
Banking rules
Official name: Luat Bao ve du lieu ca nhan - hoat dong tai chinh, ngan hang, thong tin tin dung · Law No. 91/2025/QH15 · Act of parliament
Banks, finance companies and credit bureaus must collect only what the credit-information job needs. They may not score or rank a person without consent. And they must tell the customer when their banking or credit information leaks.
Enforced by State Bank of Vietnam
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Get consentCredit information may not be used for scoring, ranking or creditworthiness assessment without the person's consent.
- Tell affected peopleTell the customer when bank, finance or credit information leaks or is lost.
- Secure the dataMeet the safety and confidentiality standards set for banking and finance, and be able to restore customer data that is lost.
Sources
- Official sourceGovernment Portal of Viet NamPersonal data protection in finance, banking and credit information under Law No. 91/2025/QH15
xaydungchinhsach.chinhphu.vn
“Khong su dung thong tin tin dung cua chu the du lieu ca nhan de cham diem, xep hang tin dung ... khi chua co su dong y cua chu the du lieu ca nhan.”
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Rules for sending data abroad
Official name: Luat Bao ve du lieu ca nhan · Law No. 91/2025/QH15 · Act of parliament
This is Vietnam's general privacy law, in force since 1 January 2026. It bans the sale of personal data outright. It ties cross-border transfers to a filed impact assessment. And it sets penalties as a share of turnover rather than a cash cap.
Enforced by Ministry of Public Security
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Get consentConsent is the default. A short list of exceptions covers emergencies, national security, state administration and agreed arrangements.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Put a transfer safeguard in placeCross-border transfer impact file.
- Delete data after a periodEmployee data must be erased or destroyed when the contract ends, unless law or agreement says otherwise.
- Get a parent's consent for children — applies at: From age 7 the child must agree as well as the legal representative before private information is published
- Tell affected peopleExplicit for leaks of banking, finance and credit information.
What it costs if you get it wrong
- Percentage of global turnover: 5% of the organisation's revenue for the preceding yearBreaking the cross-border personal data transfer rules
- Fixed maximum fine: 10 times the gain obtained from the violationBuying or selling personal data
- Fixed maximum fine: VND 3,000,000,000 — about $114 thousandAny other personal data protection violation; an individual pays half
- Criminal liabilityWhere the seriousness of the conduct warrants prosecution
Sources
- Official sourceGovernment Portal of Viet NamArticles 7 and 8 of the Law on Personal Data Protection
xaydungchinhsach.chinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamNational Assembly passes the Law on Personal Data Protection, 26 June 2025, in force 1 January 2026
baochinhphu.vn
Link checked 18 August 2026
Data rules
Official name: Nghi dinh quy dinh chi tiet mot so dieu va bien phap thi hanh Luat Bao ve du lieu ca nhan · Decree No. 356/2025/ND-CP · Directly binding regulation
This decree puts flesh on the 2025 law. Its sharpest edge is licensing. If you sell personal-data handling as a service in Vietnam, you need four things. A Vietnamese company, someone living in Vietnam in charge, three qualified staff, and a police certificate.
Enforced by Ministry of Public Security
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Register or notifyA business selling personal-data handling services needs a certificate of eligibility from the Ministry of Public Security. The certificate can be revoked after 12 months of inactivity, or for failing to fix a breach.
- Appoint a data protection officerAt least three qualified people. Each needs a college degree or higher, two years' relevant experience, and training in data protection law and practice. The head of data work must be a Vietnamese citizen living in Vietnam.
- Assess high-risk projectsYou need a data handling impact file. Where data goes abroad you also need a cross-border transfer impact file. Both must pass.
- Independent audit — 1 yearAnnual assessment of compliance status and data protection trustworthiness.
- Written vendor contractIf you handle data for another company, you must require that company to get consent before the service starts.
Sources
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamConditions for organisations providing personal data processing services under Decree 356/2025/ND-CP
baochinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment Portal of Viet NamSigned copy of Decree 356/2025/ND-CP published by the Government Portal
datafiles.chinhphu.vn
Link checked 18 August 2026
Breach reporting rules
Official name: Nghi dinh Bao ve du lieu ca nhan · Decree No. 13/2023/ND-CP, articles 23 to 25 · Directly binding regulation
These are the working mechanics of cross-border transfers and breach reporting. You lodge a file with the cyber police within 60 days. You have 72 hours to report a breach. The police can inspect once a year. And they hold a standing power to switch a data flow off.
Enforced by Department of Cyber Security and High-Tech Crime Prevention (A05)
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Put a transfer safeguard in placeA transfer impact file naming both ends, the purpose, the data, the safeguards, the person's consent, and a binding document between sender and receiver. One original goes to the cyber police within 60 days of starting. You get ten days to complete it when asked.
- Report breaches to the regulator — within 72 hoursLate reports must carry an explanation for the delay.
- Assess high-risk projectsA separate data handling impact file must be kept from the moment you start.
What it costs if you get it wrong
- Order to stopThe Ministry of Public Security may order transfers abroad to stop where the data is used against Vietnam's interests or security, where the sender ignores a request to complete its file, or where Vietnamese citizens' data leaks
Sources
- Official sourceGovernment Portal of Viet NamFull text of Decree 13/2023/ND-CP on personal data protection
xaydungchinhsach.chinhphu.vn
“Bo Cong an quyet dinh yeu cau Ben chuyen du lieu ra nuoc ngoai ngung chuyen du lieu ca nhan ra nuoc ngoai trong truong hop ... de xay ra su co lo, mat du lieu ca nhan cua cong dan Viet Nam.”
Link checked 18 August 2026
Cyber security rules
Official name: Luat An ninh mang · Law No. 116/2025/QH15 · Act of parliament
The rewritten cybersecurity law took effect on 1 July 2026. It merges the 2018 cybersecurity law with the 2015 network information security law into 45 articles. The power to order storage in Vietnam and a local office sits here. It works by order, not automatically. Its implementing decree was still being written.
Enforced by Ministry of Public Security
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryNot automatic. The police ministry applies this to named service providers by order. The duty is to keep data in Vietnam, and to open a branch or representative office. We could not confirm that the decree setting out how has been issued.
- Appoint a representativeSame trigger as the storage duty.
- Report cyber incidents
Sources
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamNational Assembly passes the Law on Cybersecurity, 10 December 2025, in force 1 July 2026
baochinhphu.vn
“Luat gom 8 chuong, 45 dieu va se co hieu luc tu ngay 1/7/2026.”
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamImplementation plan listing the decrees due under the Law on Cybersecurity, including the decree detailing article 26(3)
baochinhphu.vn
Link checked 18 August 2026
Health data rules
Official name: Danh muc du lieu cot loi, du lieu quan trong · Decision No. 20/2025/QD-TTg, with criteria in Decree No. 165/2025/ND-CP of 30 June 2025, under the Law on Data · Government rules
Vietnam sorts data into 26 core categories and 18 important categories. They run from borders and defence industry to non-public health data. They also cover aerial and satellite imagery of sensitive sites, and non-public data about organisations and citizens. Most of it is held by the state, and the police ministry polices the classification.
Enforced by Ministry of Public Security
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep records of how you use dataMinistries and provinces must guide organisations in classifying their data against the two lists.
- Secure the data
Sources
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamIssuance of the list of core data and important data
baochinhphu.vn
Link checked 18 August 2026
- Official sourceGovernment e-Newspaper, Government Portal of Viet NamPlan for implementing the Law on Data, passed 30 November 2024 and in force 1 July 2025
baochinhphu.vn
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact cross-border transfer procedure and deadlines under Decree 356/2025/ND-CP
The signed copy published by the Government Portal is a scanned image. No government site we reached carries the decree as searchable text. The 60-day filing deadline and the 72-hour breach deadline in this record come from the 2023 decree. The 2025 decree may have replaced them in whole or in part.
Whether Decree 13/2023/ND-CP has been repealed by Decree 356/2025/ND-CP
We could not find a clause repealing it. So we mark the rule partly in force, rather than in force or repealed.
What article 26 of the 2025 Law on Cybersecurity actually says about storing data in Vietnam and opening a local office
The government's own implementation plan tells the police ministry to write a decree detailing article 26(3). That is the article that carried the storage and local-office duty in the 2018 law. We could not open the 2025 law's text on a government site to confirm the wording. We also could not confirm that the decree has been issued.
Whether the administrative penalties decree for cyber security and personal data protection has been issued since May 2026
The police described it as a draft on 16 May 2026, and we found no later government notice. That is why we rate enforcement as waking rather than active.
Sector localisation rules in banking, payments, insurance, securities, telecoms, cloud, gambling and mapping
The government news search returned nothing on these, and the national legal database at vbpl.vn refused our requests. We found no rule, but that is a gap in this record rather than proof that none exists. If you work in these industries, check before you rely on it.
Minimum retention periods for tax, accounting, company and security-log records
We confirmed no official source for these. Only the deletion side of the retention rules is evidenced. Treat the minimum keeping periods as unchecked.
The precise age at which a person stops being a child for data purposes
We confirmed the 2025 law's children article. That includes the rule that a child aged 7 or over must agree before private information is published. The definition of a child is set elsewhere in Vietnamese law, and we did not confirm it here.
The statute number of the Law on Data
Government sources confirm the passing date of 30 November 2024 and the start date of 1 July 2025. The official law number was not shown on the pages we could reach.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.