Personal Data Protection Policy

Cross-Border Data Transfer Rules

ARTICLE 1. LEGAL BASIS AND DEFINITIONS

1.1. Legal basis:

  • Law on Personal Data Protection 2025 (Law No. 91/2025/QH15, effective 01/01/2026);
  • Decree 356/2025/ND-CP — governing the processing and cross-border transfer of personal data and impact assessment files;
  • Data Law 2024 (Law No. 60/2024/QH15) — on cross-border data transfer and processing;
  • the Cybersecurity Law 2025 (Luật An ninh mạng 2025, Law No. 116/2025/QH15, effective 1 July 2026 — replacing the Cybersecurity Law 2018 and the Law on Network Information Security 2015) — on data storage and cybersecurity assurance;
  • Law on Electronic Transactions 2023;
  • Decree 13/2023/NĐ-CP (applicable to the extent it does not conflict with Law 91/2025);
  • GDPR (EU) 2016/679, Chapter V (Articles 44–49); SCCs under EU Decision 2021/914; PIPL (China) 2021 (Articles 38–43); the APEC CBPR framework — applied by reference to data falling within the corresponding scope.

1.2. This regulation gives detailed effect to Article 12 (cross-border data transfers) and Article 13 (impact assessments) of the Personal Data Protection Policy (PDPD), and forms part of the Terms of Service.

1.3. Definitions:

  • “Personal data” (DLCN): information that relates to or helps identify a specific individual under the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025);
  • “Cross-border data transfer”: the transfer, provision, sharing, storage or processing of Vietnamese citizens' personal data by organizations or individuals abroad, or on systems located outside Vietnamese territory;
  • "Data Controller / Data Processor": as defined in the PDPD and the Personal Data Protection Law 2025;
  • “Cross-border personal data transfer impact assessment file”: records as required by the Personal Data Protection Law 2025;
  • “TIA – Transfer Impact Assessment”: data transfer impact assessments as required by GDPR;
  • “SCC – Standard Contractual Clauses”: standard contractual clauses approved by the EC for transferring EU data to third countries.

ARTICLE 2. CONDITIONS AND PROCEDURES FOR DATA TRANSFER UNDER VIETNAMESE LAW

2.1. Conditions for transferring personal data abroad:

(a) The data subject has consented, unless the law provides otherwise;
(b) There is a data processing agreement (DPA) or binding data protection clauses with the receiving party;
(c) Apply appropriate safeguards to maintain the level of data protection;
(d) The transfer does not compromise national security or the public interest;
(e) Prepare an impact assessment dossier for the processing or transfer of personal data abroad, before or within the statutory deadline.

2.2. Procedure for preparing and submitting documents:

(a) HiTechCloud shall prepare The impact assessment file for transferring personal data abroad and send 01 original copy to Department of Cybersecurity and High-Tech Crime Prevention (A05, Ministry of Public Security) — the authority responsible for personal data protection — within the time limits set out in the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025) and Decree 356/2025/NĐ-CP;
(b) The dossier comprises: a description of the data types, the purpose, the receiving country/party, protective measures and a risk assessment;
(c) Records shall be retained, updated whenever changes occur, and produced at the request of the competent authority.

Note: the authority that receives personal data protection filings is A05 – Ministry of Public Security (Bộ Công an), not the information security regulator that previously held this role.

2.3. Domestic data storage:

(a) Under the Cybersecurity Law 2025 (Luật An ninh mạng 2025) and its implementing documents, certain categories of data and certain businesses are subject to data localization in Vietnam;
(b) HiTechCloud maintains arrangements for storing and backing up important data of Vietnamese citizens inside Vietnam in order to meet this requirement where it applies;
(c) The retention period set out in sector-specific legislation.

ARTICLE 3. INTERNATIONAL DATA TRANSFER MECHANISM (FOR DATA WITHIN GDPR SCOPE)

3.1. Standard Contractual Clauses (SCCs): for user data falling within the scope of the GDPR (EU/EEA), HiTechCloud applies SCCs under EU Decision 2021/914, comprising Module 1 (Controller → Controller), Module 2 (Controller → Processor), Module 3 (Processor → Processor), and Module 4 (Processor → Controller), depending on the role in each data flow.

3.2. Transfer impact assessment (TIA): before each new transfer of data outside the EU, HiTechCloud carries out a TIA that: (a) identifies the law of the recipient country and the extent to which local state authorities can access the data; (b) assesses the actual level of protection against EU standards (the Schrems II test); (c) applies supplementary measures where needed (encryption, anonymization); (d) produces a TIA report retained for at least 5 years; and (e) is reviewed whenever the legal position changes or a new provider is engaged.

3.3. Supplementary mechanisms: Binding Corporate Rules (BCR) within a multinational group; priority given to an Adequacy Decision when the receiving country is recognized as equivalent by the European Commission (EC); specific consent in ad-hoc cases; and vital interests, limited to health or safety emergencies.

ARTICLE 4. LIST OF PARTNERS AND RECIPIENT COUNTRIES

Partner / serviceCountryHow it appliesData type
Amazon Web ServicesUnited States / globalSCCs + DPAHosting data
Google Cloud PlatformUnited States / globalSCCs + DPAApplication data
Microsoft AzureUnited States / EUSCCs + DPAEnterprise data
CloudflareUnited States / globalSCCs + DPALog, CDN
Stripe / PayPalUnited StatesSCCs + PCI DSSPayment data
Other providersPer contractCase-by-case assessmentDepends on purpose

This list is reviewed and updated periodically. HiTechCloud prepares and maintains a corresponding impact assessment record for each data transfer flow.

ARTICLE 5. RIGHTS OF DATA SUBJECTS

Data subjects have the right to: (a) be notified that their data is being transferred abroad; (b) refuse or withdraw consent to a cross-border transfer; (c) request information about the safeguards or DPA applied; (d) complain to the Department of Cybersecurity and High-Tech Crime Prevention (A05, Ministry of Public Security) where a breach is identified; and (e) request deletion of their data and the cessation of cross-border transfers. These rights are exercised under Articles 7 and 8 of the PDPD.


ARTICLE 6. TECHNICAL PROTECTION MEASURES

Encryption in transit (TLS 1.3 or higher); encryption at rest (AES-256); anonymization/pseudonymization of data before transfer where possible; role-based access control (RBAC) at the receiving party; monitoring and logging of all cross-border data transfer activity; periodic (annual) security audits of the data-receiving partner; compliance with the ISO/IEC 27001 standard.


ARTICLE 7. VIOLATIONS AND SANCTIONS

7.1. Internal breaches: labor disciplinary action under internal rules, up to termination of employment.

7.2. Administrative penalties: under Article 8 of the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025), breaching the rules on cross-border personal data transfers may be fined up to 5% of revenue from the preceding year of the organization; for data within the scope of the GDPR, the fine can reach EUR 20 million or 4% of global turnover whichever is higher.

7.3. Criminal violations: may be prosecuted under the Penal Code 2015 (Bộ luật Hình sự 2015), for example Article 288 on illegally posting or using information on computer and telecommunications networks.

7.4. Damages: under the Civil Code 2015 and the contract terms.

These rules take effect on 1 July 2026 and supersede all previous versions. The Vietnamese version prevails.

Revision history

Current versionby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Follow category: Personal data protection policiesGet notified when new documents are added to this category.

If this article did not answer your question, please contact HiTechCloud for help.

Contact