In short
Is your customer data sitting on foreign servers? This article separates two easily-confused legal regimes — data localization under Decree 53/2022 and cross-border personal data transfer under the Personal Data Protection Law No. 91/2025/QH15 (in force 1 Jan 2026) — with the penalty framework and a compliance checklist for Vietnamese businesses using M365, Google Workspace, Slack and other cloud services.
Quick answer
**Vietnam has no single law saying "all data must stay in the country." Instead there are TWO separate regimes businesses often merge into one: (1) *data localization* — forcing certain categories of network-service providers to store data in Vietnam and set up a branch/representative office; (2) *cross-border personal data transfer* — requiring almost every organization that moves personal data to foreign servers to prepare an impact assessment.** Small and mid-sized businesses using foreign SaaS (Microsoft 365, Google Workspace, Slack, HubSpot…) usually do NOT fall under localization, but almost certainly touch the cross-border transfer regime.
The localization regime is grounded in Article 26(3) of the 2018 Cybersecurity Law, detailed in Article 26 of Decree 53/2022/NĐ-CP: three data categories must be stored in Vietnam, for a minimum of 24 months, with a branch/representative-office obligation for foreign enterprises across 11 service sectors.
The cross-border transfer regime now rests on the Personal Data Protection Law No. 91/2025/QH15 — passed by the 15th National Assembly on 26 June 2025, in force from 1 January 2026, replacing the earlier Decree 13/2023/NĐ-CP framework. It defines what counts as a cross-border transfer and sets a maximum fine of 5% of prior-year revenue for violations.
If you use cloud email, document storage, a CRM or accounting software hosted by a provider with servers outside Vietnam, the question is not "am I allowed to" — it is "have I prepared a cross-border transfer impact assessment, and do I actually control where my customers' and employees' personal data is going." This is a software asset management (SAM) item, not solely a legal-department task.
Key legal milestones and numbers
The five facts below are the backbone of this article. Each links straight to the source text so you can verify it yourself — do not trust a vendor summary without checking the law.
- Three data categories must be stored in Vietnam under Article 26(1), Decree 53/2022/NĐ-CP: personal information data; data generated by users in Vietnam; and data on users' relationships.
- A minimum of 24 months is the storage period from when the enterprise receives the request, per Article 27(1), Decree 53/2022/NĐ-CP.
- 11 service sectors can trigger a foreign enterprise's duty to store data in Vietnam and set up a branch/representative office (telecoms; data storage and sharing; domain names; e-commerce; online payment; payment intermediary; transport connection; social networks; online games; messaging/voice/video/email/chat) — Article 26(3), Decree 53/2022.
- 1 January 2026 is when the Personal Data Protection Law No. 91/2025/QH15 takes effect; the law was passed on 26 June 2025 and supersedes the approach of Decree 13/2023/NĐ-CP.
- Up to 5% of prior-year revenue for organizations violating cross-border personal data transfer rules; other violations up to VND 3 billion; buying/selling personal data up to 10 times the illicit gain — Article 8, Law 91/2025/QH15.
1. Data residency, data localization, data sovereignty — getting the words right
These three terms are used interchangeably in marketing material, leading to misunderstood obligations. They must be separated.
Data residency is simply *the country where data physically sits*. It is a technical fact — you can pick a "Singapore", "Japan" or "US" region when configuring a cloud service. On its own it is not a legal obligation, but an input for assessing compliance.
Data localization is *a legal requirement that data remain within the territory*. In Vietnam this is the regime under Article 26(3) of the 2018 Cybersecurity Law and Decree 53/2022 — but it applies only to certain categories of subjects, not to every business.
Data sovereignty is broader: data is subject to the laws of the country where it is stored OR where the data subject resides. A file on Vietnamese customers stored on a foreign server still falls within the scope of Vietnamese personal data protection law — which is why "keeping data abroad" does not exempt a business from its obligations.
Confusing the three leads to two common mistakes: small businesses think they must build a domestic data center (they usually do not fall under localization), while overlooking the impact-assessment duty when pushing HR and customer data to foreign SaaS (that duty is very real for them).
2. Decree 53/2022: which data must stay in Vietnam, and who must keep it
Data localization in Vietnam is a *subject-conditional* regime, not a universal mandate. Article 26(1) of Decree 53/2022/NĐ-CP lists exactly three data categories that must be stored in Vietnam — quoted verbatim in Table 1.
On subjects: clause 2 requires domestic enterprises to store these three data categories in Vietnam. Clause 3 applies to foreign enterprises doing business in Vietnam across 11 service sectors — they must store the data in Vietnam and set up a branch or representative office when required by a competent authority. On duration, Article 27(1) is explicit: *"the minimum storage period is 24 months,"* counted from when the enterprise receives the storage request.
The Authority of Information Security (Ministry of Information and Communications) analysis of Decree 53 stresses that the branch/office obligation for foreign enterprises does not arise automatically — it is triggered only by a written request from the specialized authority. This matters for Vietnamese businesses to get right: most SMEs that *use* cloud services do not fall under localization — that category is for large-scale network-service *providers*.

| Data category | Definition under the Decree | Concrete examples |
|---|---|---|
| a) Personal information data | Personal information data of service users in Vietnam | Full name, date of birth, ID number, phone number, address |
| b) Data generated by users | Data generated by service users in Vietnam | Account name, usage time, credit card information, email, most recent login/logout IP address, phone number tied to the account |
| c) Relationship data | Data on the relationships of service users in Vietnam | Friends and groups the user connects or interacts with |
3. The 2025 Personal Data Protection Law: cross-border transfer and the penalty framework
This is the regime that touches the most businesses, because almost every company pushes at least one type of personal data (employee email, customer records, login logs) to a cloud service with servers outside Vietnam. Article 20 of the Personal Data Protection Law No. 91/2025/QH15 defines three cases that count as cross-border personal data transfer:
(a) transferring personal data stored in Vietnam to a storage system located outside Vietnamese territory; (b) organizations/individuals in Vietnam transferring personal data to organizations/individuals abroad; (c) organizations/individuals in Vietnam or abroad using a platform located outside Vietnamese territory to process personal data collected in Vietnam. Case (c) is the one many businesses do not expect — simply using a foreign SaaS to process Vietnamese customer data already falls within the definition.
For all three cases, the data controller/processor must prepare a cross-border personal data transfer impact assessment and remain responsible for protecting the data throughout its lifecycle. On enforcement, Article 8 of Law 91/2025/QH15 sets a notable administrative penalty framework — quoted in Table 2 — with a ceiling calculated as a *percentage of revenue*, a new approach compared with the earlier fixed fines.
The Authority of Information Security's introduction to Law 91/2025 notes a relief for small businesses: small enterprises and start-ups may choose whether to perform certain obligations (Articles 21, 22 and clause 2 of Article 33) for five years from the law's effective date — except entities in the business of data processing or those directly processing sensitive personal data. It is a transitional breathing space, not a permanent exemption.

| Violation | Maximum fine | Basis |
|---|---|---|
| Violating cross-border personal data transfer rules | 5% of the organization's prior-year revenue | Article 8(4) |
| Buying or selling personal data | 10 times the illicit gain from the violation | Article 8(3) |
| Other violations in the field of personal data protection | VND 3 billion | Article 8(5) |
| Where there is no prior-year revenue / the revenue-based figure is below the ceiling | Apply the fine under clause 5 (up to VND 3 billion) | Article 8(3), (4) |
4. What SaaS/cloud users should review before 2026
The biggest obstacle is not understanding the law — it is *not knowing where your data is*. An average company uses dozens of cloud services — email, document storage, CRM, timekeeping, accounting, internal chat — each storing data in a different region, most outside Vietnam. Without an inventory, you cannot prepare an accurate impact assessment.
That is why the first step of data-sovereignty compliance coincides exactly with the first step of software asset management: build an inventory of every service that processes personal data, together with its storage region and data type. Only from that inventory can you classify which services touch the cross-border transfer regime and which have a Vietnam-hosted option. This inventory approach connects directly to the software-inventory standard we set out in [Complying with SaaS and cloud-subscription licences for Vietnamese businesses](/en/tuan-thu-license-saas-cloud-subscription-doanh-nghiep-viet), and to [BYOL — bringing software licences to the cloud](/en/byol-mang-license-phan-mem-len-cloud) when you consider running domestic infrastructure yourself.
Table 3 is a condensed checklist — usable at any scale.
| Step | What to do | Expected output |
|---|---|---|
| 1. Inventory | List every SaaS/cloud processing personal data + its storage region + data type | A service inventory table, updated periodically |
| 2. Classify | Identify which services push personal data outside Vietnam (Article 20, Law 91/2025) | A list of cross-border transfer flows |
| 3. Impact assessment | Prepare a cross-border personal data transfer impact assessment for each flow | A file kept by the business, ready to produce |
| 4. Localization check | Check whether the business falls under the 11 sectors in Article 26(3), Decree 53 | A conclusion on whether Vietnam storage is required |
| 5. Contracts & technical | Review the data processing agreement (DPA) with providers; enable encryption, access control, logging | A signed DPA + evidenced security configuration |
5. Where Dzo.software fits in
Dzo.software is not a law firm and does not replace formal legal advice. What we do is the *software asset and infrastructure management* layer beneath the compliance obligation: building an inventory of cloud services and storage regions, reviewing licences and data processing terms with providers, and advising on Vietnam-hosted storage/backup options when a business needs to bring data back onshore.
For businesses that fall under localization, or that want to proactively reduce cross-border transfer risk, we deploy storage and backup infrastructure in Vietnam — genuine software licences, e-VAT invoices, VND payment, and Vietnamese-language documentation and support. Every legal statement in this article cites primary text for you to check; before deciding, consult a lawyer on your specific situation.
Frequently asked questions
My small business uses Microsoft 365 — do I have to move data back to Vietnam? Usually not. The *localization* obligation under Decree 53/2022 applies to network-service providers in 11 sectors, not to end users. But processing your customers' and employees' personal data on infrastructure outside Vietnam falls under the *cross-border transfer* regime of Law 91/2025, which requires an impact assessment.
Is Decree 13/2023 still in force? From 1 January 2026, the Personal Data Protection Law No. 91/2025/QH15 takes effect and becomes the higher, statute-level framework. Cross-border transfer impact assessments filed under Decree 13/2023 before the law's effective date remain usable; when updated, they follow Law 91/2025.
What is the heaviest penalty? For violating cross-border personal data transfer rules, the maximum fine is 5% of the organization's prior-year revenue (Article 8(4), Law 91/2025). Buying or selling personal data can be fined up to 10 times the illicit gain; other violations up to VND 3 billion.
How do "data residency" and "data localization" differ? Data residency is just where data physically sits — a technical choice. Data localization is a legal requirement that data stay within the territory. You can choose Vietnam as your data residency without being legally forced to; conversely, if you fall under localization, you are required to keep data in Vietnam.
Sources
- Full text of the 2018 Cybersecurity Law (Law No. 24/2018/QH14) — Article 26
- Decree 53/2022/NĐ-CP detailing the Cybersecurity Law — Articles 26 and 27
- Personal Data Protection Law No. 91/2025/QH15 (VN-EN) — Articles 8 and 20
- Authority of Information Security (MIC): Decree 53/2022 — detailed guidance on data localization in Vietnam
- Authority of Information Security (MIC): Law No. 91/2025/QH15 — the 2025 Personal Data Protection Law
Need a software compliance review?
DZO experts provide a free compliance roadmap within 24 hours — e-VAT invoice, local implementation.
Book a free consultation



