Country:越南 · Data Privacy
Vietnam · Data Privacy
Vietnam's Personal Data Protection Decree (PDPD, effective 2023) governs personal-data processing, sets strict cross-border transfer conditions, and shows a 'important data' localisation tendency. It requires a dual assessment with China's PIPL.
Key points
- PDPD (2023): applies to processing Vietnam personal data regardless of where the processor is located.
- Cross-border transfer: impact assessment, standard contractual clauses, and filing/approval with A05 (Ministry of Public Security).
- Consent: explicit consent required for sensitive data.
- Localisation tendency: important/critical data expected to be stored domestically (sector rules in progress).
- Penalty: administrative fine and possible suspension.
- China data-export duty (pkulab-verified 2026-07): transferring data back to China requires one of three paths — security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, 2025-10-14); 2024–2025 relaxation: the 'Provisions on Promoting and Regulating Cross-Border Data Flows' (Order 16) and 'Network Data Security Management Regulation' (State Council Order 790) exempt some scenarios.
Procedure
- Data inventory and classification (general/sensitive).
- Privacy policy and consent mechanism.
- Cross-border: DPIA + standard contract + A05 filing.
- Data-subject rights response mechanism.
- Designate a data-protection contact.
Hard requirements
- Consent; cross-border assessment and filing; special protection for sensitive data.
Costs
Compliance build; filing cost.⏱ ⏱ Timeline:Compliance framework before launch.⚠ Common risks
- Unfiled cross-border transfer → penalty and suspended transfer.
- Important-data localisation细则 refined → non-compliance.
- Conflict with PIPL (see data topic).
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese-invested entities operating in Vietnam, processing Vietnam personal data (wherever the processor is located), or transferring Vietnam personal data back to China (governed by the PDPD and the 2025 Personal Data Protection Law).
Prerequisites
- Clarify data categories processed in Vietnam (general/sensitive).
- Determine controller/processor role.
- Reserve impact-assessment and A05 filing budget.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data inventory and classification Inventory personal data; distinguish general vs sensitive; build a processing record. | Legal / IT | 2–3 weeks | Internal | Data inventory, classification table | Sensitive data needs explicit consent Penalty:Mis-classification加重 liability |
| 2 | Privacy policy and consent mechanism Publish a Vietnamese privacy policy; obtain processing consent (explicit for sensitive data). | Legal | 1–2 weeks | Internal | Privacy policy, consent record | Verifiable and traceable Penalty:Administrative penalty and suspension |
| 3 | Data Processing Impact Assessment (DPIA) Complete the DPIA per PDPD Article 9 and submit via the A05 national portal (https://baovedlcn.gov.vn). | Legal / compliance | 2–4 weeks | Internal / lawyer | DPIA report, A05 portal submission | Annual public-security credit rating Penalty:No assessment / no submission → penalty |
| 4 | Cross-border transfer: DPIA + standard contract + A05 filing Before cross-border transfer, complete the Cross-Border Transfer Impact Assessment (CB-TIA), sign standard contractual clauses, and file/obtain approval with A05 (Ministry of Public Security). | Legal | 3–6 weeks | Filing / lawyer | CB-TIA, standard contract, A05 filing receipt | Transfer back to China must also link PIPL export mechanism Penalty:Unfiled transfer may be suspended and penalised |
| 5 | Data-subject rights response Build access, correction, deletion and consent-withdrawal response flows. | DPO / support | Ongoing | Internal | DSAR process | Written record required Penalty:Refusing response → penalty |
| 6 | Designate data-protection contact Appoint a reachable data-protection officer/contact liaising with A05. | Management | Ongoing | Labour | Contact appointment & publication | Recommend an operational function Penalty:Regulatory liaison gap |
| 7 | Ongoing compliance and annual assessment Cooperate with A05 annual credit rating; conduct periodic review and training. | Compliance | Annual | Internal | Annual assessment & training | Important data shows localisation tendency Penalty:Persistent violation → accumulated penalties |
✅ Self-check list
⚠ Common pitfalls
Cross-border transfer without A05 filing影响:Ordered to suspend transfer and penalised.规避:Complete CB-TIA, sign contract and file first.
Ignoring the 2025 Personal Data Protection Law upgrade影响:Compliance basis失效.规避:Update policies per the new law.
Ignoring PIPL export for China-bound transfer影响:Dual violation.规避:Handle China-side export mechanism in parallel.
Sensitive data with only implied consent影响:Consent invalid.规避:Obtain explicit consent.
No A05 annual credit-rating preparation影响:Rating hurts operations.规避:Standardise and retain evidence early.
Misjudging localisation as gov-only data影响:Important-data violation.规避:Watch sector rule rollout.
📅 Ongoing post-incorporation obligations
- Cooperate with A05 annual credit rating.
- Maintain cross-border transfer filing validity.
- Sustain data-subject rights response.
- Periodic staff training and policy review.
- Keep China-bound PIPL export mechanism valid.
🔗 Official portals
📎 Source:https://www.mic.gov.vn ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.