Skip to content
Blog

Transferring personal data abroad under the PDPL: records, process and penalties

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··6 min read
Transferring personal data abroad under the PDPL: records, process and penalties

Photo: Z / Unsplash

From 1 January 2026, the Personal Data Protection Law (Law 91/2025/QH15) and Decree 356/2025/ND-CP impose one of the strictest obligations in the new framework: the duties that apply when personal data is transferred abroad. This is the highest-penalty category in the entire law, so any organization using international cloud services, SaaS software, email platforms, CRMs, or AI tools hosted outside Vietnam needs to understand exactly where it stands. The worrying part is that most businesses do not realize they are transferring data abroad at all, because it happens quietly inside the software they use every day.

This article explains what actually counts as a cross-border transfer (including offshore cloud), the impact assessment dossier you must prepare, the procedure, the penalties, and how to reduce your exposure in a durable way.

What counts as transferring personal data abroad

Many people picture a cross-border transfer as emailing an attachment to a partner in another country. That view is far too narrow and leads businesses to underestimate their exposure.

In practice, storing and processing the personal data of people in Vietnam on systems located outside the country also counts as a transfer abroad. That means:

  • Using an international cloud service to hold your customer database, HR records, or sales data when the storage region sits overseas.
  • Using SaaS software (CRM, HRM, accounting, customer support, business email) whose provider hosts servers abroad.
  • Using AI services called through an API to a model running on offshore infrastructure, where the content you send contains personal data.
  • Backing up, syncing, or analyzing data on a platform whose data centers are outside Vietnam.

The key point: what matters legally is the technical reality that data leaves the territory, not how you label the activity. A company may believe it "only uses internal software," but if that software is a cloud service whose data lives in an overseas data center, then legally the personal data has already gone abroad. This is why the initial review step matters so much: many transfer flows are buried deep inside third-party contracts and configurations.

The transfer impact assessment dossier

The central obligation for a cross-border transfer is preparing a transfer impact assessment, commonly abbreviated as TIA. This duty is set out in Article 18 of Decree 356/2025/ND-CP.

Who must file. Every organization or individual that transfers the personal data of Vietnamese citizens or residents abroad, whether acting as data controller, data processor, or both. The obligation does not depend on whether you consciously "send data out"; it attaches to the fact that data is processed or stored overseas.

What the dossier contains. In essence, the impact assessment must describe the full transfer activity clearly and truthfully, including:

  • Details of the transferring party and the overseas recipient, plus the responsible point of contact.
  • The categories of personal data transferred and the purpose of the transfer.
  • The legal basis for the transfer and the data subjects' consent, where that is the basis relied on.
  • An assessment of the risks to the rights and interests of the data subjects, together with the protective measures in place.
  • A commitment to apply data protection measures and a plan for handling incidents.

When to file. Under Article 18, an organization must file an original dossier with the specialized personal data protection authority (Department A05, Ministry of Public Security) within 60 days of starting the transfer. The 60 days run from the date the transfer takes place, not from when collection or processing began. After filing, the business must keep the dossier ready to present to the competent authority on inspection, and update it whenever the scale, data categories, or recipient change.

Keep in mind that this dossier is not a one-off permit you obtain and forget. It is a living document that reflects the organization's actual state of transfers and must be kept accurate.

The procedure

To put this obligation into practice, a business can follow four steps:

  • Step 1 — Map the data flows. Chart every piece of software, service, and vendor that processes personal data, and identify which ones store or process it abroad. This is usually the most demanding step because many flows hide inside third-party tools.
  • Step 2 — Establish the legal basis. For each transfer flow, clarify the legal basis, secure valid consent from data subjects where required, and be transparent that data may be transferred abroad.
  • Step 3 — Prepare the impact assessment. Draft a TIA for each transfer activity, describing the content above and the protective measures in full.
  • Step 4 — File and maintain. File the original dossier with A05 within the 60-day window, keep it ready for inspection, and update it when the transfer activity changes.

Penalties for violations

Breaching the cross-border transfer rules is the most heavily sanctioned category in the whole law. The maximum fine can reach up to 5% of the organization's prior-year revenue. This ceiling is reserved for the cross-border transfer tier; it is not the level applied to every PDPL violation, many of which have their own, lower brackets. Tying penalties to revenue mirrors the spirit of Europe's GDPR: enough to deter even large enterprises.

For an organization with revenue in the hundreds of billions to trillions of dong, 5% is a sum that cannot be shrugged off, on top of the reputational damage. Because the penalty scales with revenue, cross-border transfer risk is no longer an IT matter alone but a board-level issue. To understand exactly how this figure applies and to which violation groups, see what "fines up to 5% of revenue" under the PDPL really means.

Reduce the risk: keep data in-country

The most durable way to ease the compliance burden is to limit sending personal data abroad in the first place. When software and data run on-premise or on infrastructure located in Vietnam, that part simply creates no cross-border obligation: no TIA to prepare for that flow, no exposure to the 5% penalty tier, and control that is easy to prove under inspection.

This does not mean abandoning every international service; it means classifying deliberately. Sensitive and high-volume personal data should be kept in-country as a priority, while whatever genuinely needs an overseas service gets a complete dossier. This classification narrows the compliance scope down to the part you cannot avoid. See why in-country data storage is trending.

Short checklist

  • Map every piece of software and service processing personal data, flagging which store or process it abroad.
  • For each outbound flow, establish the legal basis and secure valid consent from data subjects.
  • Prepare a transfer impact assessment (TIA) for each transfer activity.
  • File the original dossier with A05 within 60 days of starting the transfer; keep it ready to present.
  • Update the dossier when data categories, scale, or the recipient change.
  • Prioritize keeping sensitive and high-volume data in-country to narrow the compliance scope.

How Tetra helps

Tetra eOffice and Molly run on-premise, keeping data in your own systems instead of pushing it onto overseas infrastructure, which narrows exactly the part most likely to trigger a cross-border obligation. To review your own status and the foundational steps, see the PDPL compliance checklist for businesses, or book a consultation for help mapping your specific situation.

Note: this article is for reference only and is not a substitute for legal advice; businesses should check the current legal texts and consult legal experts.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist