Law on Personal Data Protection, cross-border transfer
Law No. 91/2025/QH15, Article 20
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 9 months, effective 1 January 2026.
A cross border transfer rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal data of an individual in Vietnam, including biometric data, to a recipient outside the country must satisfy Article 20's cross-border transfer conditions; a violation risks a fine of up to 5 percent of the organization's prior-year revenue, a materially higher tier than the Law's general penalty.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 20 enumerates the cases in which cross-border transfer of personal data is permitted; whether its conditions include an adequacy standard, a government approval requirement, or a data-localization element is not established.
A separate penalties article confirms a materially strict enforcement posture: the maximum fine for an organization violating cross-border transfer regulations specifically is 5 percent of the organization's prior-year revenue, distinct from and higher than the Law's general violation fine tier.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
Read the law
Government Portal (chinhphu.vn) citation
substantive text read via a private secondary translation (LuatVietnam)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.