What the investor needs to understand
- Every employer and every consumer-facing business processes personal data. Vietnam's personal data protection regime applies to foreign-invested companies and, in defined cases, to offshore entities processing data of people in Vietnam.
- This area changed substantially in 2025-2026. All instruments and deadlines (confirm with counsel).
Key items
| Topic | What the investor needs to know | When it matters | Authority |
|---|---|---|---|
| Personal data protection: core duties | Lawful basis and consent rules; notices; data-subject rights; security measures; breach notification; processor contracts | Before collecting data | Ministry of Public Security (personal data protection authority) |
| Impact assessment dossiers | Data processing impact assessment and, for transfers abroad, a cross-border transfer impact assessment: prepare, keep and file as required | From start of processing / transfer | As above |
| Data protection officer / department | Appointment required in defined cases; exemptions and grace periods for small and start-up enterprises (confirm with counsel). | Set-up | As above |
| Data Law: core and important data | Classification of data; conditions on cross-border transfer of core / important data | System design | Ministry of Public Security |
| Cybersecurity: data localisation and local presence | Certain service providers must store defined data in Vietnam and may be required to establish a presence upon request (confirm under current cybersecurity legislation with counsel) | Service design | Ministry of Public Security |
| Sector rules (finance, health, telecom, e-commerce, AI) | Additional data and system-security duties in regulated sectors; emerging AI-specific rules | Licensing; operation | Sector regulator |
| Beneficial owner information | Collect, keep and file beneficial owner information with the business registration authority; update on change | ERC and ongoing | Business Registration Office |
| Anti-money-laundering and anti-corruption | Reporting entities have AML programmes; all companies need anti-bribery controls, including for dealings with officials | Ongoing | State Bank of Vietnam; Government Inspectorate |
| Competition | Merger-control notification thresholds; restrictive agreements; abuse of dominance | M&A; commercial contracts | National Competition Commission |
| Corporate housekeeping | Statutory registers, annual owner / shareholder decisions, updates to ERC / IRC on change, licence renewals calendar | Ongoing | Business Registration Office; Investment registration authority |
Common pitfalls
- Copy-pasting a GDPR programme without localising consent and filing requirements.
- Transferring HR data to the parent without a transfer assessment.
- No owner for the licence-renewal calendar.
Legal status reviewed as of 18 September 2026. Confirm current rules with counsel before acting.