Updated: 23 September 2026
Subscribing to foreign-branded software is not enough to determine transfer obligations. Check where data is stored and processed, who receives it and who can actually access it. Conversely, contracting with a Vietnamese legal entity does not prove that processing always remains in Vietnam.
Which situations count as cross-border transfers
Article 20 of the Personal Data Protection Law covers moving data stored in Vietnam to overseas storage, transferring it to overseas organisations or individuals, and using platforms outside Vietnam to process personal data collected in Vietnam. Review processing flows beyond manual file uploads.
For a CRM, clarify the primary storage region, backup locations, remote support access, subcontractors and data sent to analytics tools. Technical architecture and contracts must be consistent. “The server is in Vietnam” does not resolve every flow if overseas support teams or ancillary tools still receive data.
Dossier requirements and filing deadlines
Under Article 20, the obligated party must prepare a transfer impact assessment dossier and send one original to the specialised personal data protection authority within 60 days of the first transfer. The dossier is prepared once and updated as required; a new filing is not required for every transmission.
Article 18 of Decree No. 356/2025/ND-CP prescribes a report using Form No. 09, an application using Form No. 01a or 01b, and relevant agreements, contracts and documents. The dossier must explain the transferor, recipient, purposes, data, transfer activities, responsibilities, safeguards, risks and mitigation of adverse effects.
Submission may be online, in person or by post as prescribed. Assessment takes 15 days; the completion period following a request is 30 days. Filing does not replace the processing basis, contracts or safeguards required throughout the service period.
Understanding the employee data exception
Article 20(6) exempts an agency or organisation from preparing a transfer impact assessment dossier when storing its own employees' personal data on cloud services. This is a narrowly scoped exception, not an exemption from all employee data protection obligations, and it does not automatically extend to customer data.
Article 17 of Decree No. 356 specifies additional cases. Apply the correct subject, purpose and conditions. If an HR platform also receives applicant, dependant or customer data, assess each group and activity separately rather than apply one conclusion to the entire platform.
Cloud contracts must follow the data flows
Article 12 of Decree No. 356 requires clarity on roles, processing flows, safeguards, processing periods, deletion and data subjects' rights. Cloud data must be encrypted in storage and in transit, with strict access controls. Providers have obligations concerning subcontractors and annual compliance assessments.
A practical check is to ask how the provider deletes data at contract end, handles backups and notifies changes to subcontractors. This supports dossier updates and operational assignments; it does not mean choosing a particular brand automatically ensures compliance with Vietnamese law.
Identify transferors and recipients within corporate groups
A Vietnamese company allowing its overseas parent to access data must assess the actual flow under Article 20. Common group membership does not remove obligations, and the main server's location is not the only criterion. Clarify rights to view, export, copy, analyse and onward-transfer data.
An intragroup agreement allocates responsibilities but does not create a processing basis for a new purpose. Using employee records for payroll and using them to train AI, for example, require separate assessment. The exception for storing an organisation's own employee data on cloud services should not be extended to every analytics activity of the parent company.
What to check after preparing a transfer dossier
Beyond personal data protection, assess Data Law classifications, cybersecurity requirements, sector-specific confidentiality and contractual usage restrictions. Article 42(3) of Decree No. 356 avoids duplicate assessments in specified cases; it does not remove every other obligation.
A practical question for a provider is: when a customer requests deletion or the contract ends, how does each party holding a copy handle the data? The answer directly connects transfer documentation with cloud responsibilities and individual rights procedures.
Frequently asked questions
May data be transferred abroad? The law does not impose a blanket ban on every activity. Meet the conditions, documentation requirements and safeguards applicable to the data type, sector and circumstances.
If data is both important data and personal data, are two identical assessments required? Article 42 of Decree No. 356 amends Decree No. 165 to apply personal data protection impact assessment documentation in specified cases, avoiding duplicate risk and impact assessment dossiers under Decree No. 165. Other safeguards must still be checked.
Legal sources
Personal Data Protection Law No. 91/2025/QH15
Decree No. 356/2025/ND-CP implementing personal data protection requirements
Decree No. 165/2025/ND-CP implementing the Data Law
Cybersecurity Law No. 116/2025/QH15
Sources checked through 23 September 2026.
Related articles
Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026
Article 04 Vietnam Personal Data Processing Impact Assessment Requirements
Article 07 Vietnam Data Law and the Classification of Core and Important Data
Article 19 Vietnam Cloud Service Notification and Data Protection Responsibilities
Article 21 Vietnam Personal Data Protection Templates and How to Use Them
