Cross-Border Data Transfer
Law on Personal Data Protection — cross-border transfer of personal data
Vietnam · January 1, 2026
Verify detailsVietnam's definition of a transfer is the part that catches businesses out. Decree 356 treats as a cross-border transfer not just sending data to a foreign recipient but STORING personal data on server systems located outside Vietnam or on a foreign provider's cloud service, and processing Vietnamese-collected data on overseas platforms — so ordinary use of a non-Vietnamese SaaS or cloud region is in scope. Transfers require a cross-border transfer impact assessment dossier, which must be kept available for inspection by the data protection authority and submitted within 60 days of the transfer. Decree 356 exempts several categories, including cross-border personnel management, transfers to fulfil legal obligations, and transfers to perform contracts or procedures for cross-border transport, logistics, remittance and payment. Penalties for cross-border transfer violations run to 5% of the previous year's Vietnamese revenue. Marked 'check': the Law and Decree are very recent, the primary texts are Vietnamese-language, and enforcement practice does not yet exist.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.