TL;DR: Vietnam data laws - the Data Law and the Personal Data Protection Law (PDPL) - now require all data generated by Vietnamese organizations to be stored and processed on-shore. Tens of thousands of businesses running email, CRM, and cloud tools on US, Singapore, or EU servers are in direct violation, facing heavy fines, executive criminal liability, and data exposure to foreign governments under laws like the US CLOUD Act.
What Changed? The Two Landmark Vietnam Data Laws
Two Vietnam data laws now define the compliance baseline for every business operating in Vietnam:
- Luật Dữ liệu (Data Law) establishes that all data generated by Vietnamese organizations and individuals, including customer records, transactions, contracts, internal communications, and email content, is classified as national digital sovereignty. The law mandates this data be stored and processed within Vietnamese territory.
- Luật Bảo vệ Dữ liệu Cá nhân (Personal Data Protection Law, PDPL) sets strict rules for any transfer of personal data across borders. Cross-border transfers require a completed Data Protection Impact Assessment (DPIA), separate explicit consent from each data subject, a binding data processing agreement with the foreign recipient, and prior approval from the Ministry of Public Security (Bộ Công an).
Together, the Vietnam data laws mark a decisive turn toward digital sovereignty in Vietnam. The question for businesses is not whether to comply, but how quickly they can close the gap.
Why Foreign SaaS Puts You Outside Vietnam Data Laws by Default
Most international SaaS platforms, whether Google Workspace, Microsoft 365, Salesforce, HubSpot, or their equivalents, run on servers in the US, Singapore, or the EU. None of them offer a Vietnam data region. The moment a Vietnamese company uploads a customer’s name, phone number, email address, purchase history, or internal communication to one of these platforms, that data crosses the border.
Under the Vietnam data laws, that crossing is only permitted after completing a set of compliance steps that the overwhelming majority of Vietnamese businesses have never taken. As Nguyễn Đức Toàn, Executive Committee Member of the Ho Chi Minh City Information Technology Association (Hội Tin học TP.HCM), wrote in a recent analysis: most businesses still think “buy the software and use it stably,” completely unaware their data has quietly left the country.
Three Hidden Risks in Vietnam Data Laws Most Businesses Underestimate
1. The CLOUD Act conflict
US law, specifically the CLOUD Act and FISA Section 702, gives US authorities the legal right to compel any US-based technology company to extract and hand over data, regardless of where that data is physically stored. A Vietnamese business storing its financial records or customer database on a US SaaS platform can have that data accessed by US government authorities without the Vietnamese company being notified. This is not a hypothetical risk; it is the legal architecture those platforms operate under.
2. Operational fragility
Vietnam’s undersea cable infrastructure has experienced repeated outages in recent years. A business whose entire CRM, email, and document workflow runs through international servers faces a complete operational blackout during any cable failure. Local infrastructure eliminates this single point of failure.
3. Executive liability, not just fines
Vietnam data laws do not limit accountability to the company. In serious data incidents involving core business data, individual executives can face direct criminal charges under Vietnamese law. The cost is not just a financial penalty; it can include reputational damage, loss of partner trust, and personal legal exposure for the people who signed off on the technology choices.
What Compliant Cross-Border Transfer Actually Requires

For businesses that genuinely need to work with international tools, Vietnam data laws lay out a specific compliance checklist. It is not lightweight:
- Complete a DPIA specifically for the cross-border data flow
- Obtain separate, granular consent from each individual data subject for cross-border transfer
- Execute a binding data processing agreement (DPA) with the foreign SaaS provider that meets Vietnamese law, not just GDPR or US standards
- File for and receive approval from the Ministry of Public Security before transferring data abroad
Most international SaaS vendors will not help you build the documentation Vietnam data laws demand. Their compliance frameworks are designed for GDPR and US federal law. When a data incident occurs, the Vietnamese company bears 100% of the legal liability under domestic law.
How Data-Native Businesses Are Staying Ahead

The shift toward compliance with Vietnam data laws is not just about avoiding fines. Organizations that move to on-shore, locally governed data services gain a concrete operational advantage: full auditability, lower latency, immunity from international legal conflicts, and a defensible compliance posture for regulators, auditors, and enterprise customers who ask to see your data governance framework.
DataCore’s data products and services are built on Vietnamese-hosted infrastructure, governed under Vietnamese law, and structured to support the compliance requirements of the Data Law and PDPL. For organizations in banking, financial services, corporate supply chain, and government, our Company Intelligence Service and data-domain subscriptions provide decision-grade data without cross-border transfer exposure.
See also: DataCore blog for more on Vietnam’s digital transformation regulatory landscape.
A 90-Day Roadmap to Align with Vietnam Data Laws
For most mid-sized companies, aligning with Vietnam data laws is a quarter-long program rather than a weekend migration. Days 1-30: inventory. Map every system that stores or processes data of Vietnamese customers or employees - email, CRM, HR, analytics, backups - and record where each one physically hosts data. Days 31-60: classify and prioritize. Separate core data covered by the Data Law from personal data covered by the PDPL, then rank systems by legal exposure and by how hard they are to move.
Days 61-90: remediate. Migrate the highest-risk workloads to on-shore infrastructure, execute cross-border transfer assessments for what legitimately must remain abroad, and assign a named executive owner for ongoing compliance. Regulatory scrutiny of data flows is a global trend - we saw the same pattern in our analysis of Virginia’s geolocation data ban - and the direction of travel is one-way. Official texts of both laws are published on the government portal at chinhphu.vn.
The practical payoff of early alignment with Vietnam data laws goes beyond avoiding fines: procurement teams at banks and state-linked enterprises increasingly require on-shore hosting as a condition of doing business, so compliance is becoming a sales asset rather than a cost center.
FAQ
Do Vietnam data laws apply to foreign companies operating in Vietnam?
Yes. Vietnam data laws apply to any organization conducting activities in Vietnam that generate data from Vietnamese individuals or transactions occurring in Vietnam, regardless of where the company is headquartered.
What is the fine for non-compliance with the PDPL’s cross-border transfer rules?
Vietnam data laws set administrative fines by violation category - the PDPL defines the categories. For unauthorized cross-border data transfers, penalties can run into hundreds of millions of VND per violation, with the severity scaling based on the sensitivity of the data and the scale of the breach. Criminal liability applies in serious cases.
Are Vietnamese-language SaaS tools automatically compliant with Vietnam data laws?
Not automatically. Under Vietnam data laws the key criterion is where data is stored and processed, not the language of the interface. A Vietnamese-branded SaaS platform that stores data on AWS Singapore or Google US-East is still a cross-border transfer under the Data Law.
Can we comply with Vietnam data laws while still using some international tools?
Yes. Vietnam data laws allow it, but the process is procedurally heavy: DPIA, explicit consent, DPA with the foreign vendor under Vietnamese law standards, and Ministry of Public Security approval. Most organizations find the total compliance cost higher than migrating to domestic alternatives for core data workloads.
What is the realistic timeline before enforcement ramps up?
Both laws are already in force, and enforcement historically follows a pattern in Vietnam: a grace period of soft guidance, followed by high-profile inspections of large consumer platforms, then broader sweeps through mid-market sectors. Companies that wait for the first headline enforcement case typically end up doing a rushed migration at premium cost. Building the inventory and classification work now - the cheap part of compliance - preserves the option to move quickly when scrutiny arrives.
Where should a small team start if budget is tight?
Start with email and file storage, because they hold the densest concentration of personal data and are the systems inspectors ask about first. Vietnamese-hosted alternatives exist at price points comparable to international suites, and migrating them delivers the largest single reduction in exposure under Vietnam data laws. CRM and analytics can follow in a second phase once the core communication stack is on-shore.
The document trail inspectors expect to see
When regulators assess compliance with Vietnam data laws, they look for a paper trail rather than promises. In practice that means a current data inventory that names every system holding Vietnamese personal or core data, a data classification policy that distinguishes PDPL categories from Data Law categories, completed impact assessments for any transfer that leaves the country, signed data processing agreements with every foreign vendor still in the stack, and evidence of a named executive owner with authority over the program.
None of these documents is individually difficult to produce, but assembling them retroactively during an inspection window is where companies get hurt. Teams that maintain the trail as part of normal vendor onboarding treat each new tool as a small compliance decision instead of accumulating a large hidden liability. That habit, more than any single migration, is what separates organizations that handle Vietnam data laws calmly from those that scramble.







Để lại một bình luận
You must be logged in to post a comment.