Vietnam’s Cybersecurity and Data Compliance Framework: What Foreign Companies Need to Know

Vietnam’s data compliance landscape is entering a new phase, with the Personal Data Protection Law (PDPL), the Cybersecurity Law (CSL), the Data Law (DL), and their guiding documents creating an increasingly comprehensive regulatory framework. Unlike the GDPR, Vietnam’s framework covers not only personal data protection but also cybersecurity, data classification, and government management. For foreign companies operating in Vietnam, non-compliance can result in significant consequences, including administrative fines that may be calculated by reference to revenue, restrictions on cross-border data transfers, and other remedial measures. Therefore, companies should understand Vietnam’s data rules as a separate legal framework rather than simply applying the GDPR or other international standards.

A key feature of Vietnam’s framework is the interaction between multiple laws.The CSL establishes baseline requirements for network security and the protection of information systems, particularly where national security, cybersecurity, and critical information systems are concerned. The DL introduces a classification system for general, important, and core data, with obligations becoming more stringent depending on the sensitivity of the data. Meanwhile, the PDPL provides the comprehensive framework for personal data protection, covering areas such as lawful processing, data-subject rights, consent, sensitive personal data, and breach notification. In practice, a single data-processing activity may trigger obligations under all three regimes simultaneously, meaning that cybersecurity, data classification, and personal data protection cannot be treated as entirely separate compliance workstreams.

For companies processing personal data in Vietnam, the PDPL sets out several practical requirements. Some of these requirements are similar to those under the GDPR, but there are important differences. Consent remains important for many private-sector processing activities and must be informed and specific. Companies must clearly inform data subjects about the purpose and method of processing, retention periods, and their rights. Sensitive personal data, including biometric, financial, health, and location data, requires additional care and appropriate compliance measures. Companies must also prepare and maintain a Data Protection Impact Assessment (DPIA) dossier and update it when their processing activities change. In addition, companies processing personal data must appoint a Data Protection Officer (DPO) or a designated department and formally submit the relevant information to the authorities. As a result, compliance requires more than simply having a privacy policy. Companies also need practical procedures for consent, data assessments, and responding to data-subject requests.

Cross-border data transfer is one of the most complex areas of Vietnam’s data compliance framework. Companies transferring personal data outside Vietnam must prepare and formally submit a Cross-border Transfer Impact Assessment (CTIA) dossier to the Ministry of Public Security (MPS) within 60 days from the date of the first cross-border personal data transfer (or from the date of data processing activities commencement). The dossier must include information about the sender and recipient, the legal obligations of the foreign recipient, and the technical measures used to protect the data. Companies must also continue to meet their compliance obligations, including updating the authorities when there are changes to their data processing or transfer activities. For international businesses, this means that Vietnam’s requirements may need to be considered together with data protection rules in other countries. For example, EU–Vietnam data transfers may need to comply with both the GDPR requirements on the EU side and Vietnam’s CTIA requirements. Unauthorized cross-border transfers may result in serious penalties, including fines of up to 5% of the violator’s revenue in Vietnam in the previous year.

On the other hands, foreign companies should also consider data localization and information security requirements when setting up their operations in Vietnam. Under the CSL and related regulations, certain foreign companies providing telecommunications, internet, and value-added services may be required to store user data in Vietnam and establish a local office or representative office in Vietnam as required by law. The CSL also requires information systems to meet certain technical and management standards to protect against cyber espionage and unauthorized data extraction. At the same time, the DL’s data classification system affects how different types of data must be handled. These requirements may affect a company’s IT systems, vendors, data management, and incident response. It is therefore more practical and cost-effective to consider these requirements when setting up the system from the beginning rather than making changes later.

Enforcement is becoming increasingly important for companies operating in Vietnam. The MPS, particularly the A05 department, is the lead regulator, while sector-specific authorities may impose additional requirements. Companies must respond quickly to data breaches or investigations and comply with applicable notification requirements. Therefore, data compliance should be treated as an ongoing process rather than a one-time documentation exercise.

For foreign companies, Vietnam’s developing data framework highlights the need to build cybersecurity and data compliance into business operations from the beginning. Companies should review their data flows under the PDPL, CSL, and DL, maintain DPIA and CTIA documents where required, and consider data localization and information security requirements. Understanding and following Vietnam’s local framework will help companies manage regulatory risks and maintain compliant operations.