Updated: 23 September 2026
Personal data, important data and core data are classifications based on different criteria. A dataset may belong to several categories at once. Businesses must examine its content, scope and impact rather than assume important data simply means commercially valuable records.
What the Data Law regulates
Data Law No. 60/2024/QH15 took effect on 1 July 2025. Article 13 addresses classification; Article 15 data governance; Article 23 cross-border transfer and processing; Article 25 risk management; and Article 27 data protection. Articles 39–43 also regulate data products and services.
Decree No. 165/2025/ND-CP implements many requirements. Read it alongside relevant amendments, particularly Decree No. 356/2025/ND-CP where core or important data is also personal data.
Identifying core and important data
Article 3 defines these concepts by their impact on national defence, security, foreign affairs, the macroeconomy, social stability, public health and safety. Decision No. 20/2025/QD-TTg provides the classification lists. Do not classify data solely because it feels very important to the company.
A practical approach is to inventory datasets and describe their sector, source, scale, aggregation level, geographical scope and responsible person. Then check the exact list entry, including any conditions or thresholds. A shop's customer file and a large aggregated dataset may lead to different assessments.
Classification should follow the data throughout its use. An initially small dataset may be combined with multiple sources. Reassess content, identifiability and classification criteria at that point rather than retain the original conclusion because the filename is unchanged.
Additional responsibilities for personal data
If data relates to or helps identify a specific person, assess the Personal Data Protection Law. Obligations concerning processing grounds, individual rights, security and impact assessments may apply simultaneously. Inclusion in a Data Law category does not remove individual rights under the specialised law.
Use the term de-identification precisely. Article 2(1) and (11) of the Personal Data Protection Law provides that de-identified data is no longer personal data. By contrast, anonymisation under Article 9(3)(c) of Decree No. 356 involves separating and storing identifying information separately; this does not automatically remove the data from protection. Encryption, replacing names with codes or partially masking information is also insufficient to establish de-identification.
Are duplicate cross-border assessments required
Article 42(3) of Decree No. 356 amends Article 16(2) of Decree No. 165. Where core or important data transferred or processed across borders is personal data, the responsible entity prepares personal data processing and transfer impact assessment dossiers under personal data protection law, without performing the cross-border risk and impact assessments under Decree No. 165.
This resolves overlapping documentation requirements. It is not a complete exemption from data governance or protection responsibilities. For non-personal data, return to the corresponding provisions of the Data Law and Decree No. 165.
Who coordinates compliance within a business
Operational managers should work with data, IT and legal teams to identify the responsible entity, users, recipients and controls. The Ministry of Public Security is the lead data regulator under the Law; each filing must follow its specific procedure. Sending a general inventory does not fulfil every obligation.
Can data be used freely once it is no longer personal data
A de-identified report may still contain trade secrets or be subject to contractual usage restrictions. Conversely, a dataset without information about individuals may still qualify as core or important data. One classification does not answer every other classification question.
For example, a business combining partners' data into an analytics product must examine rights to use source data, identifiability in the output and the service's regulatory framework. Delivery through cloud services or use in AI creates further corresponding obligations. The data analysis and aggregation article connects classification with the rules for supplying the product.
Frequently asked questions
Is all commercially valuable data important data? No. Apply the statutory definition and lists.
Does the Data Law require all data to be stored in Vietnam? No general requirement can be inferred. Storage and transfer duties depend on the data, parties, activities and relevant rules.
Legal sources
Decree No. 165/2025/ND-CP implementing the Data Law
Decision No. 20/2025/QD-TTg on core and important data
Personal Data Protection Law No. 91/2025/QH15
Decree No. 356/2025/ND-CP implementing personal data protection requirements
Sources checked through 23 September 2026.
Related articles
Article 05 Overseas Cloud and CRM Services and Vietnam Data Transfer Filings
Article 08 Vietnam Data Analytics Licensing Changes from 15 September 2026
Article 17 Using Customer and Employee Data in AI under Vietnamese Law
Article 19 Vietnam Cloud Service Notification and Data Protection Responsibilities
Article 20 Vietnam and EU Data Protection and AI Laws Compared by Obligation
