Security

Decree 53 vs Decree 13: cybersecurity storage vs personal data protection

Two Vietnamese decrees are constantly confused, and if you are running a server or a digital service that touches Vietnam, confusing them can cost you. Decree 53/2022/ND-CP (usually called Decree 53) and Decree 13/2023/ND-CP (often referred to as Decree 13 or the Personal Data Protection Decree, PDPD) sit on different legal foundations, regulate different activities, and carry different penalties. One is about keeping cybersecurity-related data inside the country. The other is about how you handle a person’s name, phone number, and browsing history. This article breaks down the exact differences so you know which obligations apply to your infrastructure, your software stack, and your business processes.

第53号法令管网络安全存储,第13号法令管个人数据保护。

Decree 53 covers cybersecurity storage; Decree 13 covers personal data protection.

What is Decree 53, the cybersecurity data storage law?

Decree 53 is a 2022 implementation of Vietnam’s Cybersecurity Law (Law 24/2018/QH14). Its core purpose is data localisation for specific categories of data related to national cybersecurity. It requires that certain organisations, particularly those providing telecom, internet, and online services in Vietnam, store specific types of data physically inside Vietnam for a defined period.

The key requirement: if you are a telecom operator (like Viettel, VNPT, or FPT Telecom), a social network, a search engine, an online advertising service, or a cloud/hosting provider operating within Vietnam’s cyberspace, you may be required to store personal data (as defined broadly), data about user relationships, and data generated by user activity on servers located in Vietnam for at least 24 months. The data must be retained for a minimum of 12 months after the storage period expires, in a form that allows the authorities to request it within 48 hours.

Decree 53 applies to both domestic and foreign enterprises. If a foreign company provides services that fall into one of the listed categories and has a user base accessing from Vietnam, it must establish at least one server in Vietnam and comply with the storage timeline. The penalty for non-compliance ranges from administrative fines (up to several hundred million VND) to suspension of service in Vietnam.

What is Decree 13, the Personal Data Protection Decree (PDPD)?

Decree 13, enacted in April 2023 and effective from July 2023, is Vietnam’s first comprehensive standalone regulation on personal data protection. It is built on the principles of the EU GDPR but adapted to Vietnam’s legal and operational context. It governs how personal data, any information that can identify a specific individual, is collected, processed, stored, shared, and transferred across borders.

Decree 13 applies to any entity, whether in Vietnam or abroad, that processes personal data of Vietnamese data subjects. That includes a VPS operator in Singapore whose server stores a database of Vietnamese customers, or a marketing agency in Ho Chi Minh City that runs a CRM. The key obligations are:

  • Consent: you must obtain explicit, informed, and revocable consent from the data subject before processing their personal data.
  • Data Protection Impact Assessment (DPIA): for high-risk processing activities (e.g., profiling, large-scale monitoring), you must conduct and file a DPIA with the Ministry of Public Security.
  • Cross-border data transfer: before transferring personal data of a Vietnamese data subject abroad, you must file a transfer impact assessment with the authorities and maintain records for the full transfer lifecycle.
  • Breach notification: you must notify the authorities within 72 hours of a personal data breach.
  • Data subject rights: individuals can request access, correction, deletion, restriction, and portability of their data, and can object to processing.

Penalties under Decree 13 are steep, up to 5% of total revenue (not profit) for the most serious violations, or up to VND 100 million (approximately $4,000 as of 2026) for certain administrative offences involving sensitive personal data. The PDPD also introduces criminal liability for intentional violations that cause serious harm.

Where do they overlap?

The overlap is in the term “personal data.” Decree 53 uses a broad definition of personal data as part of the data that must be localised. Decree 13 uses a more granular, GDPR-style definition that distinguishes between basic personal data (name, phone number, email, ID number) and sensitive personal data (political opinions, health data, biometric data, sexual orientation, criminal records). If you are a telecom or internet service provider, Decree 53 forces you to store all that data inside Vietnam. Decree 13 then dictates how you handle it, consent, cross-border transfer, breach notification, regardless of where the server sits.

In practice, a company offering a social network or a cloud service in Vietnam must comply with both: physically store user data on a Vietnam-based server (Decree 53) and implement the full PDPD compliance program for consent, DPIA, and transfer assessments (Decree 13). A hosting provider like Viettel IDC (viettelidc.com.vn) or FPT Telecom (fpt.vn) typically offers colocation and VPS services in Tier-3 datacenters inside Vietnam; choosing such a facility is one step toward Decree 53 compliance, but it does nothing for Decree 13 obligations.

How do they differ, a comparison table

Criteria Decree 53 (Cybersecurity Data Storage) Decree 13 (Personal Data Protection)
Primary focus National cybersecurity: keep specific data physically inside Vietnam Individual privacy: regulate how personal data is collected, processed, and transferred
Legal basis Cybersecurity Law 2018 Standalone personal data protection (PDPD)
Types of data covered Personal data, user relationship data, user activity data, and other cybersecurity-related data Basic personal data (name, phone, email, ID) and sensitive personal data (health, biometric, political, etc.)
Geographic requirement Data must be stored on a server physically located in Vietnam for at least 24 months No blanket localisation requirement; cross-border transfers are allowed after filing a transfer impact assessment
Duration of obligation Store for 24 months; retain for 12 months after expiry (total 36 months minimum) Ongoing, applies for the entire lifecycle of processing, plus retention periods defined by other laws
Key procedural requirement Establish a branch or representative office in Vietnam; maintain a server here Obtain consent, file DPIA for high-risk processing, file cross-border transfer assessment, notify breach within 72 hours
Authority Ministry of Public Security (Department of Cyber Security) Ministry of Public Security (Department of Cyber Security and High-Tech Crime Prevention)
Penalty Administrative fines up to several hundred million VND, service suspension Up to 5% of total revenue, fines up to VND 100M, criminal liability for severe violations
Who it applies to Telecom operators, social networks, advertising services, cloud/hosting providers, online games (listed categories) Any entity, domestic or foreign, that processes personal data of Vietnamese data subjects
Cross-border data transfer Not directly addressed; the requirement is local storage, not blocking transfer Explicitly regulated: must file a transfer impact assessment before sending personal data abroad

Which decree applies to whom and when?

If you are a foreign cloud provider serving Vietnamese users, say a Singapore-based company renting out VPS instances to Vietnamese customers, Decree 53 likely does not apply unless you fall into one of the listed categories (telecom, social network, advertising, etc.). But Decree 13 applies to you the moment you process any personal data of a Vietnamese individual, even if the server is in Singapore. You need consent forms, a DPIA if your processing is high-risk, and a transfer impact assessment before any data leaves Vietnam (if your server is outside the country).

If you are a Vietnamese company hosting its own applications, for example, an e-commerce site running on a VPS hosted at Viettel IDC (viettelidc.com.vn), Decree 53 generally does not apply unless you are a listed service provider. Decree 13, however, applies to every customer-facing operation that collects names, phone numbers, addresses, or payment information. You need a privacy policy, consent mechanisms, and a breach response process.

If you are a social network or instant messaging service (like a local competitor to Facebook or Zalo), both decrees apply. You must store user data on a Vietnam-based server (Decree 53) and comply with the full PDPD framework (Decree 13). That typically means running your own infrastructure in a Vietnamese datacenter, possibly through a colocation arrangement or by renting a VPS with dedicated IPv4 within Vietnam, and also hiring a data protection officer to handle consent and breach notifications.

Practical implications for VPS and hosting users

If you are reading this and run any server that touches Vietnam, whether as a hosting provider, an app developer, or an internal IT administrator, here is what you should do today:

  • Map your data: identify what personal data of Vietnamese data subjects you collect and where it is stored. If any of it is personal data (even a name and phone number), Decree 13 applies.
  • Check your hosting location: if you are a listed service provider under Decree 53 (social network, telecom, advertising, cloud hosting), your data must be in a Vietnamese datacenter. Using a VPS from a domestic provider like VinaHost (vinahost.vn), Mat Bao (matbao.net), or thueVPS (thuevps.vn) that offers NVMe storage and a Vietnamese IPv4 is a viable path.
  • Document consent: for Decree 13 compliance, you need a consent mechanism that allows users to opt in, opt out, and withdraw consent. This is a software change (update your registration page and privacy policy), not a hardware one.
  • Prepare a cross-border transfer file: if you plan to transfer personal data outside Vietnam (e.g., to a backup server in Singapore), prepare a transfer impact assessment and file it with the authorities.
  • Monitor for updates: Decree 13’s implementation guidelines are still being clarified as of 2026. The Ministry of Public Security periodically releases circulars that adjust thresholds, timelines, and exemptions.

FAQ

Do I need to comply with both decrees if I only run a small blog?

If your blog collects email addresses for a newsletter, you are processing personal data under Decree 13. You need a privacy policy and a consent mechanism. Decree 53 only applies if you are a listed service provider (telecom, social network, etc.), which a typical blog is not.

Can I avoid Decree 53 by hosting my service in Singapore or Hong Kong?

If Decree 53 applies to your category of service, the law requires you to have a server in Vietnam. Hosting outside Vietnam does not exempt you, it creates a direct violation. Check if you fall into one of the listed categories; if you do, you need a Vietnam-based server.

What is the penalty for violating Decree 13?

Fines can reach up to 5% of your total revenue (not profit) for serious violations involving sensitive personal data, or up to VND 100 million for certain administrative offences. Criminal liability is also possible for intentional violations that cause serious harm, such as a data breach affecting thousands of people.

Does using a Vietnamese hosting provider automatically make me compliant with both decrees?

No. A Vietnamese hosting provider, like Viettel IDC or thueVPS, gives you a server physically inside Vietnam, which can help with Decree 53’s storage requirement. But Decree 13 compliance requires entirely different steps: consent forms, DPIA, transfer assessments, breach notification. The hosting company cannot do those for you, they are procedural and legal obligations you must fulfill.

How do Vietnam’s major telecom operators, Viettel, VNPT, FPT, interact with these decrees?

Viettel (viettel.com.vn), VNPT (vnpt.com.vn), and FPT Telecom (fpt.vn) are the three largest telecom and internet service providers in Vietnam. As telecom operators, they are explicitly listed under Decree 53 and must store all relevant data inside their own Vietnamese datacenters. They also process massive amounts of personal data for their millions of subscribers, so Decree 13 applies to their customer-facing operations. Many foreign companies use them for colocation or connectivity services.

Bài viết liên quan

Disclaimer: This article provides general information about Vietnamese legal regulations and is not intended as legal advice. The interpretation and enforcement of Decree 53 and Decree 13 can vary based on specific facts and regulatory guidance. You should consult a qualified lawyer practicing in Vietnam for advice tailored to your particular situation and infrastructure.

Note: This guide is for general reference. Every system and infrastructure has its own specifics, so test each step in a safe environment and consult a qualified engineer before applying it in production.

第53号法令与第13号法令的区别

两部法规经常被混淆。第53号法令属于网络安全范畴,管的是数据存储和配合调查;第13号法令是个人数据保护法,管的是收集、使用和跨境传输。企业通常两者都要遵守,但应对方式完全不同。