Personal data, cybersecurity and compliance

Personal data, cybersecurity and general corporate compliance from day one.

What the investor needs to understand

  • Every employer and every consumer-facing business processes personal data. Vietnam's personal data protection regime applies to foreign-invested companies and, in defined cases, to offshore entities processing data of people in Vietnam.
  • This area changed substantially in 2025-2026. All instruments and deadlines (confirm with counsel).

Key items

TopicWhat the investor needs to knowWhen it mattersAuthority
Personal data protection: core dutiesLawful basis and consent rules; notices; data-subject rights; security measures; breach notification; processor contractsBefore collecting dataMinistry of Public Security (personal data protection authority)
Impact assessment dossiersData processing impact assessment and, for transfers abroad, a cross-border transfer impact assessment: prepare, keep and file as requiredFrom start of processing / transferAs above
Data protection officer / departmentAppointment required in defined cases; exemptions and grace periods for small and start-up enterprises (confirm with counsel).Set-upAs above
Data Law: core and important dataClassification of data; conditions on cross-border transfer of core / important dataSystem designMinistry of Public Security
Cybersecurity: data localisation and local presenceCertain service providers must store defined data in Vietnam and may be required to establish a presence upon request (confirm under current cybersecurity legislation with counsel)Service designMinistry of Public Security
Sector rules (finance, health, telecom, e-commerce, AI)Additional data and system-security duties in regulated sectors; emerging AI-specific rulesLicensing; operationSector regulator
Beneficial owner informationCollect, keep and file beneficial owner information with the business registration authority; update on changeERC and ongoingBusiness Registration Office
Anti-money-laundering and anti-corruptionReporting entities have AML programmes; all companies need anti-bribery controls, including for dealings with officialsOngoingState Bank of Vietnam; Government Inspectorate
CompetitionMerger-control notification thresholds; restrictive agreements; abuse of dominanceM&A; commercial contractsNational Competition Commission
Corporate housekeepingStatutory registers, annual owner / shareholder decisions, updates to ERC / IRC on change, licence renewals calendarOngoingBusiness Registration Office; Investment registration authority

Common pitfalls

  • Copy-pasting a GDPR programme without localising consent and filing requirements.
  • Transferring HR data to the parent without a transfer assessment.
  • No owner for the licence-renewal calendar.

Legal status reviewed as of 18 September 2026. Confirm current rules with counsel before acting.

Terms used on this page

Other topics