Updated: 23 September 2026
Cloud computing raises more than the question of server location. Providers must identify the service notification regime, while customers and providers must separately allocate responsibility for data, configuration and access. Telecommunications and data protection requirements can apply together.
Whom domestic providers notify
Article 29 of the Telecommunications Law and Article 45 of Decree No. 163/2024/ND-CP establish notification for services within scope. Article 21 of Decree No. 133/2025/ND-CP delegates receipt of certain notifications to the provincial People's Committee where the enterprise has its head office.
Section IV of Annex I to Decree No. 133 sets the procedure, including Form No. 05. Section B.II of Annex II to Resolution No. 20/2026/NQ-CP reduces the response period for invalid dossiers to two working days. This is a dossier feedback deadline, not a licence confirming that all cloud activities comply with law.
Businesses also registering data centre services should check the mechanism for including notification information in that registration. Changes of information and cessation must be tracked under applicable provisions rather than simply retaining the initial notice.
Do cross-border providers still have information duties
Section B.XXXIV of Annex II to Resolution No. 20/2026 provides that organisations under Article 45(1)(b) of Decree No. 163 do not follow the administrative notification procedure in paragraphs 3–4. However, before supplying services, they must still notify information to the Ministry of Science and Technology through the Vietnam Telecommunications Authority.
Information includes name, head office address, contact point, service type and service quality commitments for cloud and data centre services. Saying that abolition of the procedure means foreign providers need submit nothing does not fully reflect the new rules.
Who is responsible for personal data in the cloud
Article 12 of Decree No. 356/2025/ND-CP requires contracts to identify processing flows, roles, responsibilities and safeguards. Cloud personal data must be encrypted in storage and transit with strict permissions. Providers must require subcontractors to meet relevant duties and conduct personal data protection compliance assessments once a year.
Customers must ensure processing grounds, purposes, retention periods and individual rights within their responsibility. Providers are responsible according to their roles and services. If processing occurs outside Vietnam, also check Article 20 of the Personal Data Protection Law and cross-border transfer dossiers under Decree No. 356.
Lessons from international shared responsibility models
AWS describes a shared responsibility model in which the provider is responsible for cloud infrastructure within its scope, while customers have corresponding responsibility for data, configurations and service use. The precise division changes by service. This is one provider's technical and contractual description, not a conclusion that it meets every Vietnamese legal requirement.
Its practical value is requiring clarity about who does what. A provider may operate servers while a customer configures data store read permissions. If access is too broad, responsibility must be assessed against actual settings, contracts and applicable law. A general claim of security cannot replace that allocation.
Contract terms to review
Clarify data locations, remote support, subcontractors, key management, backups, recovery, incident notification times, audit rights and end-of-contract data handling. Read availability service-level agreements separately from privacy and security commitments; meeting one metric does not establish compliance with another.
Cloud contracts should anticipate switching providers
Data migration, return, deletion and copy handling should be defined from the outset. Retention periods must also match the customer's purposes and sector-specific duties. Avoid promising immediate deletion of every copy before discovering that the backup design cannot deliver it.
A provider may store data on instructions for one activity while independently deciding how to use some logs for another. Determine roles by purpose; infrastructure shared responsibility models do not replace classification under Articles 2 and 37 of the Personal Data Protection Law.
Adding AI on the same platform requires checking new flows, training uses and parties' access. The AI and personal data article explains changes that an initial cloud contract may not cover.
Frequently asked questions
Does cloud notification authorise all uses of customer data? No. Data purposes and processing rights need their own legal basis.
Does a cloud location in Vietnam guarantee no cross-border transfer? Not necessarily. Check backups, support, subcontractors and flows beyond the main server location.
Legal sources
Telecommunications Law No. 24/2023/QH15
Consolidated Instrument No. 19/2026/VBHN-ND-BKHCN implementing the Telecommunications Law
Decree No. 133/2025/ND-CP on delegation of authority in science and technology
Resolution No. 20/2026/NQ-CP on procedural reduction and simplification
Personal Data Protection Law No. 91/2025/QH15
Decree No. 356/2025/ND-CP implementing personal data protection requirements
AWS explanation of the shared responsibility model
Sources checked through 23 September 2026.
Related articles
Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026
Article 05 Overseas Cloud and CRM Services and Vietnam Data Transfer Filings
Article 12 Vietnam Information System Security Level Dossiers and Approval Authorities
Article 17 Using Customer and Employee Data in AI under Vietnamese Law
Article 18 Vietnam Data Centre Services Registration and Licensing
