Storing and protecting data: how long to keep, when to delete?

Photo: Luke Caunt / Unsplash
This article summarizes legal provisions for reference only and does not replace professional legal advice. Retention periods and specific obligations vary by sector and by record type — check the source texts and get professional counsel for your organization's situation.
Many organizations think data compliance is only about "don't leak information". But read closely and Vietnamese law sets up two groups of obligations that pull in opposite directions:
- Some laws require you to keep records and data for years.
- The Personal Data Protection law requires you to delete data once it no longer serves its purpose.
Keep too much and you breach data-protection duties. Delete too much and you breach retention duties, losing evidence during a tax audit or inspection. This piece untangles exactly that: which law forces you to keep, which forces you to delete, and how to reconcile them in practice.
Four groups of obligations to know
1. Records retention — the 2024 Law on Archives
The 2024 Law on Archives (No. 33/2024/QH15) took effect on 1 July 2025, replacing the 2011 law. The most notable point for organizations going digital: the law formally recognizes electronic records — records created as data messages — as archival objects on par with paper.
In other words, moving to a digital office does not remove the retention duty; it shifts that duty into electronic form, with requirements to preserve integrity, authenticity and long-term readability.
2. Sector-specific retention periods — accounting records as an example
Many fields have their own retention periods. The clearest is accounting: Article 40 of the 2015 Law on Accounting and Decree 174/2016/ND-CP set three tiers:
- At least 5 years — accounting vouchers not used directly for bookkeeping and financial statements; routine documents.
- At least 10 years — vouchers used directly for bookkeeping and financial statements, accounting books, annual financial statements.
- Permanent — documents of historical, economic, security or defense significance.
Other sectors (healthcare, HR, construction, banking...) have their own frameworks. The common thread: retention is counted in years, not "whenever it's convenient to delete".
3. In-country data storage — the Cybersecurity Law and Decree 53/2022
Article 26 of the 2018 Cybersecurity Law and Decree 53/2022/ND-CP require storing data in Vietnam (data localization) for domestic and foreign enterprises providing services over telecom networks, the Internet and value-added services in cyberspace. Two points are often misread:
- This duty does not apply automatically to every business. It arises when there is a written request from the authority (the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security), tied to a specific violation.
- Once triggered, the minimum storage period is 24 months, counted from receipt of the request until it ends. Foreign enterprises in scope must also establish a branch or representative office in Vietnam.
Even without such a request, this is a practical reason many organizations choose to keep important data on in-country infrastructure from the start.
4. Protecting and deleting personal data — the 2025 PDPL
The opposite pull comes from the Law on Personal Data Protection (No. 91/2025/QH15) and Decree 356/2025/ND-CP. Alongside duties on consent, data-subject rights and processing security, the law sets a principle central to retention:
- Minimization: collect and keep personal data only to the extent needed for the declared purpose.
- Purpose limitation: when the processing purpose is fulfilled or the subject withdraws consent, personal data must be deleted or destroyed (unless another law requires keeping it).
- Data subjects have the right to request deletion; organizations must have a mechanism to respond.
On top of this, the 2024 Law on Data (No. 60/2024/QH15), effective 1 July 2025, acts as the overall data-governance framework — classification, management, sharing — within which the above obligations operate.
The knot: "must keep" and "must delete" at once
Put side by side, the conflict shows: an invoice carrying a customer's name, address and personal tax code — the Law on Accounting says keep it at least 10 years, the PDPL says delete when the purpose is done. Keep or delete?
The right approach is not to pick a side, but to understand priority and scope:
- The statutory retention duty wins within its scope. The PDPL allows keeping personal data when "another law provides otherwise" — the 10-year accounting-retention duty is exactly that. You must not delete the invoice to satisfy a deletion request.
- But the data you keep must be locked to its purpose: used only for accounting/tax duties, never for marketing, never shared beyond scope.
- When the statutory retention period ends, the PDPL deletion duty kicks back in. Data may not be "kept forever just in case".
In short, each data type has a lifecycle — kept long enough under the law that requires keeping, then deleted under the law that requires deleting. Most organizations' problem is that no one is managing that lifecycle systematically.
What to do: a "retention schedule" for your organization
You don't need a big legal department. You need a living retention schedule:
- Inventory your data. List the record and data types you hold (accounting, contracts, HR, customer data, system logs).
- Attach a retention basis to each type. For example: bookkeeping vouchers kept 10 years (Law on Accounting); unsuccessful applicant records by purpose and consent (PDPL); security logs by request (Decree 53).
- Set deletion dates. Each type has an expiry and an action at expiry (delete, anonymize, or move to historical archives).
- Log everything. Who accessed, who deleted, when — to prove compliance in both directions.
- Choose where to store. For sensitive data or data at risk of a localization request, favor in-country infrastructure with controllable backups and access rights.
- Anonymize instead of keeping raw. When you only need aggregate figures (statistics, reports), anonymize personal data to leave the PDPL's scope while keeping analytical value.
What a document-management system must do
A retention schedule on paper dies within months. It only survives if a system enforces it for people. When evaluating an eOffice or document-management platform, ask whether it can:
- Attach a retention period and deletion date to each document type, and remind or act automatically at expiry?
- Keep full access and action logs to prove compliance?
- Manage electronic records to archival standards (integrity, authenticity, long-term readability)?
- Allow keeping data in-country with controllable backups and access rights — rather than sitting on foreign infrastructure under a third party's policy?
This is also why the on-premise / self-hosted model suits organizations handling sensitive data: you keep data in-country, you can prove the retention–deletion lifecycle, and you don't depend on an outside provider's policy.
Conclusion
Data compliance in Vietnam is not one law but four interlocking groups of duties: records retention (Law on Archives 33/2024), sector periods (Law on Accounting and equivalents), in-country storage (Cybersecurity Law and Decree 53/2022), and protecting and deleting personal data (PDPL 91/2025 and Decree 356/2025), within the governance framework of the Law on Data 60/2024.
The task is not to memorize the law, but to know how long each type of your data lives and when it dies — then let a system enforce that lifecycle instead of relying on memory. Organizations that do this are safe both under inspection and under the PDPL.
If you are building retention and data-protection processes for your organization, book a consultation to align them with your actual operations and the right deployment model.
Related articles

Transferring personal data abroad under the PDPL: records, process and penalties
The 2026 PDPL sets strict obligations for transferring personal data abroad, with the highest penalty of up to 5% of revenue. When it applies, what to file, and how to reduce risk with on-premise.
Read ↗
Deploying eOffice on-premise: data sovereignty seen from the architecture
Data sovereignty is more than servers located in Vietnam. A look at the architecture, infrastructure, integration and staffing behind an on-premise eOffice.
Read ↗
PDPL review season: impact assessment records and the DPO role
After PDPL took effect, businesses enter a review season: impact assessment records, the DPO role, and reviewing data transfers out.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.