Call Us: +84 903419479

Contact Center

+84 903419479

Vietnam Personal Data Protection Law 2026 Compliance Guide for Foreign Companies

Foreigners 02/10/2026

This guide explains how Vietnam personal data protection law 2026 may affect foreign companies, foreign-invested enterprises and overseas parent companies. It highlights common data risks, cross-border transfer concerns and practical compliance steps before collecting, sharing or transferring personal data.

Vietnam has adopted the Law on Personal Data Protection No. 91/2025/QH15, which becomes a key legal framework for personal data processing activities in Vietnam from 2026. This development is particularly relevant for foreign companies, foreign-invested enterprises, overseas parent companies and international service providers that collect, store, access, share or transfer personal data relating to individuals in Vietnam.

This does not mean every company will have identical obligations. The legal position may depend on the role of the company, the type of personal data involved, the purpose of processing, the scale of activities, the transfer structure and the business model. However, foreign companies should not treat data privacy as a purely technical issue. In many cases, personal data protection in Vietnam is now a legal, operational, HR, commercial and governance concern.

For foreign investors entering the market, data compliance should be considered alongside incorporation, employment, contracts and operational setup. Businesses planning to set up a 100 foreign owned company in Vietnam should review personal data practices at an early stage, especially where employee, customer, user or platform data will be processed.

Why foreign companies should review data compliance in Vietnam in 2026

Personal data is no longer only an IT security issue. It is increasingly a board-level and management-level compliance matter. A company may face legal, commercial and reputational risks if it collects or transfers personal data without proper internal review, documentation and control.

Many foreign companies operating in Vietnam handle personal data even if they do not consider themselves to be data businesses. A manufacturer may store employee files, payroll records and visitor logs. A trading company may maintain customer databases and supplier contact details. A representative office may keep candidate CVs, meeting records and ID documents. A SaaS provider, e-commerce operator or platform business may process user accounts, transaction records and technical data on a much larger scale.

Common examples of personal data handled by foreign companies include:

  • employee profiles, labor contracts and payroll records;

  • candidate CVs, interview notes and recruitment databases;

  • customer accounts, CRM records and marketing lists;

  • ID documents, passports, work permit files and visa information;

  • service registration forms, user profiles and platform activity records;

  • visitor logs, access records and security camera-related data;

  • due diligence files, transaction documents and business contact records.

Foreign companies should review where this data comes from, why it is collected, who can access it, where it is stored and whether it is shared inside or outside Vietnam. A company does not need to be a technology business to face Vietnam data privacy compliance concerns.

Who may be affected by Vietnam personal data protection rules

Vietnam personal data protection rules may affect many types of foreign-related businesses. The actual obligations will depend on the facts, but the issue should be reviewed whenever personal data relating to individuals in Vietnam is collected, processed, accessed or transferred.

Potentially affected parties may include:

  • foreign-invested companies incorporated in Vietnam;

  • representative offices of foreign traders;

  • foreign employers dealing with employees or contractors in Vietnam;

  • service providers working with Vietnamese users, customers or candidates;

  • overseas parent companies accessing personal data from a Vietnam subsidiary;

  • regional headquarters managing HR, compliance, accounting or customer support;

  • SaaS, fintech, e-commerce, education, healthcare, recruitment, consulting and outsourcing businesses;

  • companies transferring personal data from Vietnam to another country.

For example, a Vietnam subsidiary may store employee files locally, while its overseas parent company accesses the data through a shared HR system. A foreign SaaS company may have Vietnamese users but host its platform outside Vietnam. A recruitment business may collect candidate profiles and share them with foreign clients. An e-commerce business may store customer names, phone numbers, addresses, payment-related details and complaint histories.

In each case, the company should review its role in the processing activity. It should also identify whether it determines the purpose of processing, merely processes data on behalf of another entity, shares data with vendors, or transfers data to group companies outside Vietnam. Data protection compliance for foreign invested companies in Vietnam is therefore not a one-size-fits-all exercise.

Common personal data risks for foreign invested companies

Foreign-invested companies often face data risks because personal data is collected across several departments without one clear owner. HR, sales, marketing, finance, IT, customer service and management teams may all collect or access personal data for different reasons.

One common risk is collecting more data than necessary. Some companies request copies of identity documents, family information, financial records or health information without clearly reviewing whether all of that information is required for the stated purpose. Overcollection may increase legal and operational risk, especially where data is sensitive or retained for too long.

Another practical issue is unclear consent or privacy notices. Individuals may provide information through employment documents, customer forms, website accounts, service contracts or marketing campaigns without receiving a clear explanation of how their data will be used, shared or retained. Companies should review whether their forms, notices and internal procedures are consistent with their actual processing activities.

Employee personal data in Vietnam also needs careful attention. Employers may store contracts, salary records, performance reviews, disciplinary records, insurance documents, dependents information, bank account details and identification documents. These files should not be left in uncontrolled folders or shared drives. Access should be limited to people who genuinely need the information for a lawful and documented business purpose.

Other common risks include:

  • sharing data with group companies, vendors or platforms without proper review;

  • using foreign cloud storage without considering cross-border transfer issues;

  • retaining old employee, customer or candidate data indefinitely;

  • not knowing which departments or individuals can access personal data;

  • using customer or candidate data for marketing without reviewing the legal basis;

  • failing to update internal documents when the business model changes;

  • treating data compliance as an IT matter only, rather than a legal and management issue.

Customer data protection in Vietnam is also important for businesses that rely on CRM systems, e-commerce platforms, digital marketing tools or after-sales support. Companies should review whether customer information is used only for legitimate business purposes and whether marketing, profiling or data-sharing practices require further legal assessment.

Cross border data transfer and overseas parent company access

Cross border personal data transfer in Vietnam is one of the most important issues for foreign companies to review. Many international businesses transfer or allow access to Vietnam-related personal data outside Vietnam as part of ordinary operations.

This may happen through parent company access, regional HR systems, global payroll platforms, shared CRM tools, cloud storage, IT support, accounting software, compliance reporting or customer service centers. Even where data is not manually sent by email, overseas access through a shared system may still need to be reviewed.

Foreign companies should begin with data mapping before reaching legal conclusions. A practical review should identify:

  • what personal data leaves Vietnam or can be accessed from outside Vietnam;

  • who receives or accesses the data;

  • where the data is stored or hosted;

  • why the transfer or access is necessary;

  • whether the data includes employee, customer, user, candidate or contractor information;

  • whether sensitive or high-risk personal data is involved;

  • whether individuals have been properly informed;

  • whether contracts and internal procedures reflect the actual data flow.

Overseas parent company access deserves particular attention. A parent company may need access to Vietnam subsidiary data for financial reporting, HR management, compliance, audit, security or group policy implementation. However, the company should still review whether the access is proportionate, properly documented and consistent with Vietnam data privacy compliance expectations.

Foreign companies should avoid assuming that a group company can freely access all Vietnam data simply because it owns or manages the local entity. Internal group sharing may still create legal and compliance issues, especially where personal data is transferred across borders or made available to multiple jurisdictions.

Practical compliance checklist before collecting or sharing personal data

Before collecting, using, sharing or transferring personal data relating to individuals in Vietnam, foreign companies should carry out a practical compliance review. The objective is not only to prepare documents, but also to understand the real data practices of the company.

A useful starting checklist includes the following steps.

  1. Identify what personal data is collected
    The company should list the categories of personal data it collects, including names, contact details, identification documents, employment records, payment information, user account data, transaction records and communication history.

  2. Classify data by relationship type
    Employee, customer, user, contractor, candidate and business contact data should be classified separately. Each category may involve different purposes, risks, retention periods and access controls.

  3. Identify sensitive or high-risk data
    Certain information may create higher risk, such as identity documents, health information, children data, biometric data, precise location data or information used for profiling. Legal advice should be sought where sensitive or high-risk data is processed.

  4. Review consent forms, privacy notices and employment documents
    Companies should check whether individuals are properly informed about collection, use, sharing, storage and transfer of their personal data. Employment documents, customer forms, website notices and service terms should be reviewed against actual business practices.

  5. Map internal and external data sharing
    The company should identify which internal departments, group companies, vendors, consultants, platforms and service providers can access personal data. Informal sharing practices should also be reviewed.

  6. Review vendor and cloud service arrangements
    Foreign cloud storage, SaaS tools, payroll providers, CRM platforms, marketing tools and outsourced service providers may create data protection issues. Contracts and access arrangements should be reviewed before personal data is uploaded or shared.

  7. Check cross-border transfer practices
    The company should identify whether personal data is transferred outside Vietnam or accessed by overseas teams. Cross-border transfer structures should be reviewed before implementation, not only after a complaint or incident occurs.

  8. Set access controls and retention rules
    Access to personal data should be limited to relevant personnel. Companies should define how long different categories of data are kept and when they should be deleted, archived or anonymized.

  9. Train HR, sales, marketing, IT and management teams
    Data compliance is not effective if only the legal department understands it. HR, sales, marketing, IT and managers should understand basic rules on collection, sharing, retention and incident escalation.

  10. Obtain legal advice before high-risk processing or transfer structures
    Legal advice should be obtained before launching large-scale processing, platform services, sensitive data projects, cross-border transfer models or group-wide data sharing systems.

This checklist is not a guarantee of full compliance. It is a practical starting point for identifying legal and operational risks before they become disputes, complaints or regulatory issues.

When foreign companies should seek legal advice in Vietnam

Foreign companies should seek legal advice in Vietnam when personal data processing becomes significant, sensitive or cross-border. Early review is usually more effective than trying to correct documents and systems after a data issue has already occurred.

Legal advice is recommended where:

  • the company collects large volumes of personal data;

  • sensitive personal data may be involved;

  • employee personal data is stored across multiple systems;

  • customer or user data is used for marketing, profiling or platform services;

  • personal data is transferred outside Vietnam;

  • overseas parent companies access Vietnam data;

  • vendors, cloud providers or outsourced service providers handle Vietnam data;

  • the company operates in HR, SaaS, fintech, healthcare, education, recruitment, e-commerce or platform services;

  • there is a data incident, complaint, inspection risk or vendor dispute.

Legal review may also be needed where personal data issues overlap with commercial disputes, employment claims, customer complaints or contractual breaches. In some cases, data handling practices may become relevant in broader legal conflicts. Foreign businesses facing escalation risks may also need advice on dispute resolution for foreign companies in Viet Nam.

Vietnam personal data protection law 2026 should be treated as part of a broader compliance framework for foreign companies doing business in or with Vietnam. The right approach depends on the operations, data flows, industry, internal systems and relationship with individuals in Vietnam.

This article is for general information only and should not be treated as legal advice for any specific data processing activity.

If your company collects, stores, transfers or shares personal data relating to individuals in Vietnam, APOLO LAWYERS - Solicitors & Litigators can assist with legal review, risk assessment and practical compliance planning. Foreign investors, employers and international businesses may contact experienced lawyers in Vietnam before launching new services, onboarding vendors or transferring personal data across borders.

icon_email
phone-icon