Data compliance in Vietnam operates across overlapping legal frameworks, including the Law on Personal Data Protection (PDPL), the Cybersecurity Law (CSL), the Data Law (DL) and guiding documents.

Together, these rules create a regime that is meaningfully different from the GDPR, with data-localization requirements in certain cases, mandatory impact assessments for cross-border data transfers, and multiple regulators sharing jurisdiction. For foreign companies, the consequences of non-compliance can be serious, including administrative fines that may be calculated by reference to revenue in some cases, restrictions on cross-border data transfers, and other remedial measures. Vietnam’s data regime is not simply a local version of the rules used elsewhere; it is a separate system that must be assessed and implemented on its own terms.

Why Data Compliance in Vietnam Is Different

The CSL establishes the baseline for network security, and the protection of information systems, particularly where national security, cybersecurity, and critical information systems are involved. The DL classifies and categorizes data according to its sensitivity, particularly focusing on “important” and “core” data, and introduces strict cross-border prohibitions and state management. The PDPL is Vietnam’s comprehensive personal-data statute and sits alongside those regimes rather than replacing them. In practice, a single data-processing activity may trigger obligations under all three frameworks at the same time, which is often the first major surprise for companies entering the Vietnamese market.

The PDPL shares several concepts with the GDPR, including lawful bases, data-subject rights, and breach-notification obligations, but it differs in important operational details. Consent remains central in many private-sector processing activities, and the law is strict on notice, purpose limitation, and the handling of sensitive personal data. It also applies to certain offshore processing activities involving the personal data of individuals in Vietnam, which means companies cannot assume that an overseas structure automatically avoids Vietnamese compliance obligations. In addition, cross-border transfer assessments and other local compliance steps do not map perfectly onto GDPR mechanisms, so treating PDPL as “GDPR for Vietnam” is an oversimplification that can create compliance gaps.

Enforcement involves regulators with overlapping jurisdiction — with the Ministry of Public Security (MPS) acting as the lead — while sector authorities add their own rules for financial services, healthcare, and operators of critical information systems. Enforcement has real teeth: cross-border transfer violations can now trigger penalties up to 5% of a violator’s preceding year’s revenue in Vietnam. For a foreign company, this means compliance is not a single filing, but an ongoing posture maintained across multiple authorities.

Cybersecurity Law & Data Law in Vietnam

The Vietnamese CSL applies broadly to organizations that operate information systems or provide digital services in Vietnam. It imposes baseline security obligations, including technical and administrative safeguards, and may trigger data-localization measures or local presence requirements in certain cases if cybersecurity violations are not remedied after notice. For foreign companies, the key point is that cybersecurity compliance in Vietnam can affect infrastructure design, vendor management, incident response, and local regulatory engagement from the outset.

The DL sits alongside it, establishing a data-classification system — general, important, and core data — with escalating obligations at each level, plus strict regulatory vetting for data activities that affect national security. Together with the PDPL, these laws mean cybersecurity compliance and data protection in Vietnam are not separate workstreams: a single system can owe security obligations under the CSL, classification and handling duties under the DL, and personal-information rules under the PDPL simultaneously. For foreign-invested enterprises, the practical consequence is that IT infrastructure, data handling, and privacy practices all have to be designed against this combined data protection law framework from the outset — retrofitting compliance after a system is built is far more expensive.

PDPL Compliance: Key Obligations

PDPL compliance turns on a set of obligations that look familiar to anyone who knows GDPR but differ in the operational detail that determines whether a company is actually compliant. For many private-sector processing activities, consent remains the key basis, and consent must be informed, specific, and given after the data subject receives a clear notice of the processing purposes, methods, retention period, and their rights. Sensitive personal data requires a higher level of care, and companies should avoid relying on bundled or vague privacy-language as a substitute for properly designed consent flows.

Sensitive personal information, including categories such as biometrics, financial data, health data, and location data, may require additional internal justification and documented compliance measures. Organizations processing personal data should also maintain a Data Protection Impact Assessment dossier and be able to update it as the processing activity changes. Data subjects must be able to exercise rights such as access, correction, deletion, withdrawal of consent, and other rights recognized by the applicable Vietnamese rules. In practice, compliance requires more than a policy document; it requires a working operational process that the business can actually follow.

The PDPL also requires organizations processing personal data to appoint a Data Protection Officer (DPO) or designated department, a role whose details must be formally submitted to the authorities. Meeting these regulatory requirements is not a one-time documentation exercise; it means building consent flows, assessment processes, and a response capability for data-subject requests into how the business actually operates in Vietnam.

Cross-Border Data Transfer in Vietnam

Cross-border data transfer is the single most operationally complex part of data compliance in Vietnam. Moving personal information out of the country requires the preparation and formal submission of a Cross-border Transfer Impact Assessment (CTIA) dossier directly to the MPS within 60 days of the first transfer.

The thresholds are demanding, requiring broad compliance for nearly any outbound transfer of personal data collected within Vietnam, necessitating continuous six-month updates to the authorities. The CTIA dossier must meticulously detail sender and receiver information, the binding legal obligations on the foreign recipient, and the specific technical safeguards implemented.

In practice, the assessment is the hard case: it requires detailed data mapping, can take extensive preparation time, and is subject to active state scrutiny. For EU-Vietnam data flows, the two regimes stack — a transfer can require both a GDPR transfer mechanism on the outbound EU side and a PDPL CTIA mechanism on the Vietnam side. Getting this wrong is not theoretical: unauthorized cross-border transfers are an active enforcement priority, and the cost of an unapproved data export can be devastating fines scaling to 5% of revenue and an operational shutdown of the data flow the business depends on.

Data Localization & Security Requirements

Two requirements catch foreign companies off guard when they set up IT infrastructure in Vietnam: data localization and mandatory information security protection standards.

Data localization applies most directly under the CSL and its guiding decrees, mandating that foreign enterprises providing telecommunications, internet, and value-added services store user data in Vietnam and establish a local office if they fail to remedy cybersecurity violations upon warning. Information security standards are mandatory under the CSL, requiring network systems to carry defined technical and management requirements to prevent cyber espionage and unauthorized data extraction. Foreign companies frequently overlook these security frameworks when standing up systems in Vietnam, only to discover the obligation during an audit or a transaction. Underneath both sits the DL’s classification scheme, which determines how strictly any given dataset must be handled. Designing infrastructure and data handling against these requirements from the start is far cheaper than remediating later.

Enforcement & Regulatory Response in Vietnam

Data enforcement in Vietnam is shared among several regulators with overlapping jurisdiction. The MPS, particularly the A05 department, is the lead data and cybersecurity regulator. Sector regulators add further layers.

Enforcement has intensified, and penalties are substantial, with new frameworks allowing for massive revenue-based fines. When an investigation or a data breach occurs, the response is time-sensitive and procedural: the PDPL and the CSL impose strict breach-notification obligations on regulators, often mandating reports within 72 hours—or even 24 hours under related consumer laws. How a company handles the notification, the regulator interaction, and the remediation in the first days often determines whether an incident becomes a manageable matter or a much larger liability. Having local counsel who can manage the regulator relationship directly is the difference between a controlled response and an escalating one.

Our Role as a Cybersecurity and Data Compliance Law Firm in Vietnam

As a cybersecurity lawyer team with a permanent presence in Vietnam, we provide data compliance services to foreign enterprises that must comply with the PDPL, the CSL, and the DL simultaneously. Our practicing lawyers in Vietnam handle the relevant work locally, responding to corporate enquiries regarding data security and personal information protection, conducting compliance and data classification analyses, drafting privacy notices and policies, and assisting with the preparation and filing of CTIA and DPIA dossiers to the MPS.

A data protection lawyer on our Vietnam team also manages the regulator-facing side — responding to MPS inquiries, handling breach notifications, and representing the client in investigations — while our European and broader Asian network keeps the Vietnam program aligned with the company’s GDPR and other obligations, so EU-Vietnam data flows are handled coherently on both sides.

Because data compliance rarely stands alone, the same team draws on our corporate, employment, and contracts practices — the data clauses in a supply agreement, the employee-data side of HR, the diligence in a transaction — so a company gets one coordinated program rather than separate advice from separate firms.

Contact us for a
first consultation

CONTACT US FOR A FREE CONSULTATION

This field is for validation purposes and should be left unchanged.