Vietnam data localization: Decree 53 and PDPL for foreign firms

Your legal team forwards a compliance question, and it lands on your desk: does our Vietnam service need to store data inside the country? For any foreign firm running users, partners or a local entity in Vietnam, the answer now depends on two separate rules, Decree 53 and the Personal Data Protection Law (PDPL), and they do not cover the same ground. This post breaks down what each one actually requires, who it binds, and how to build hosting in Vietnam that satisfies it without rebuilding your whole architecture.
- Decree 53 (Decree 53/2022/ND-CP) implements the cybersecurity law and can force a foreign provider to store specified data in Vietnam and open a local branch, but only after a formal request.
- PDPL (Law No. 91/2025/QH15) is a general personal-data law that requires cross-border transfers to meet conditions, and it applies to foreign firms processing data of people in Vietnam.
- The two overlap but are not the same: Decree 53 is triggered by enforcement action, PDPL applies from day one.
- Keeping personal data of Vietnamese users on a server physically located in Vietnam is the simplest way to stay inside both regimes.
越南的数据本地化要求来自第53号法令和《个人数据保护法》两套不同规则。
Vietnam's data localization requirements come from two different rule sets: Decree 53 and the Personal Data Protection Law.
What is Vietnam data localization, in plain terms
Vietnam data localization means that certain categories of data generated in or about Vietnam must be stored on servers physically located inside the country, rather than only on infrastructure abroad. It is not a blanket rule that all data must stay in Vietnam. It is a targeted obligation that applies to specific data types and specific organisations, and it is backed by enforcement mechanisms rather than a simple registration.
The distinction matters because a lot of foreign firms either overreact (moving everything into Vietnam unnecessarily) or underreact (assuming that because they have no Vietnamese entity, nothing applies). Both are wrong. What applies depends on who your users are, what data you hold, and whether you have ever received a formal request from the authorities. For most SaaS and e-commerce operations serving Vietnamese customers, the practical exposure comes from holding personal data of people inside Vietnam, which is where the PDPL sits.
Localization is really one requirement inside a wider compliance picture: identifying the data, choosing where it lives, proving the flows, and being able to move or delete on request. Hosting choice is only one layer, but it is the layer you control fastest.
Decree 53: the trigger, not the default
Decree 53/2022/ND-CP is the implementing decree for Vietnam's cybersecurity framework. The important thing to understand is that it does not automatically order every foreign firm to keep data locally. It creates a mechanism: the authorities can identify a provider whose services are being used to violate Vietnamese law, and after a process, request that the provider store certain data in Vietnam and establish a local presence.
The categories Decree 53 cares about are broad but specific: personal data of service users in Vietnam, data created by users in Vietnam (messages, uploads, relationship data), and data about the user's relationships. If you operate a platform where Vietnamese users interact, that is exactly the kind of data in scope. A hosting provider or a pure infrastructure reseller is generally not the target; the target is the service sitting on top.
The mechanics matter for planning. The obligation normally arrives as a written request, and it comes with a compliance period. Once you are on that list, retrofitting infrastructure under a deadline is expensive and stressful. The firms that handled it well were the ones who already had a Vietnamese node, a local entity or partner, and a documented data map, so the request became an implementation task rather than an emergency migration.
Who it realistically touches
If you run a social, messaging, marketplace, fintech or gaming service with a meaningful Vietnamese user base, assume Decree 53 is in your threat model. If you run B2B infrastructure, internal tooling, or a website with no stored personal data of Vietnamese users, the odds are far lower. Do not self-assess on the title of the decree alone; look at what data you actually persist about people inside Vietnam.
The PDPL: the rule that applies from day one
Vietnam's Personal Data Protection Law (PDPL) is the broader and more immediately relevant instrument for foreign firms. Unlike Decree 53, you do not wait for a request: if you process personal data of individuals in Vietnam, the law is relevant to you as soon as you do it. Its core obligations are the familiar ones, consent, purpose limitation, security, breach notification, and rights of the data subject, but the cross-border transfer condition is what makes hosting decisions a compliance decision.
Under the PDPL, transferring personal data out of Vietnam requires that you meet the legal conditions for that transfer, typically documented through an impact assessment or transfer agreement, and that the receiving side provides protection at an adequate level. In practice this means you cannot simply dump Vietnamese user data into a foreign cloud region and call it done. You must be able to show what leaves the country, why, and under what safeguards.
This is where the architecture choice gets concrete. If the personal data stays on servers in Vietnam, the transfer question often does not arise for that dataset, and your compliance paperwork gets materially simpler. If it does leave, you need the documentation trail that proves the conditions were met. Most foreign firms end up with a split: personal data held locally, aggregated or anonymised analytics processed wherever is cheapest.
Why the two rules are not interchangeable
Decree 53 is enforcement-driven and provider-focused; the PDPL is rights-driven and applies to any organisation processing personal data of people in Vietnam. A firm can be fully clear of a Decree 53 request and still be non-compliant with the PDPL because of how it transfers data overseas. Treat them as two separate checklists, not one.
Building compliant hosting inside Vietnam
The technical answer to both regimes is the same: put the in-scope data on infrastructure that physically sits in a Vietnamese datacenter, with full control over disks, backups and access. That is a standard Linux VPS or Windows VPS in a Tier 3 facility, and for larger data volumes a dedicated server Vietnam.
What you should insist on is not just "in Vietnam" but verifiable control of the data path. You want NVMe storage you administer, a dedicated IPv4 in the Vietnam range so your traffic and reverse DNS are clearly local, full root or Administrator access so you can encrypt, snapshot and audit yourself, and monthly billing so you can stand the node up quickly when a legal review demands it. Colocation is the other option if you already own hardware and want it racked locally; see our notes on colocation Vietnam for the rack-level constraints.
| Requirement | Decree 53 | PDPL |
|---|---|---|
| Who it applies to | Service providers named after an enforcement process | Any org processing personal data of people in Vietnam |
| Trigger | Formal written request + compliance deadline | Applies from the moment you process the data |
| Core obligation | Store specified data in Vietnam and establish local presence | Meet conditions for cross-border transfer; protect data subject rights |
| Applies to foreign firms | Yes, if the service is in scope | Yes, regardless of local entity |
| Practical mitigation | Keep a local node and a documented data map ready | Host personal data locally; document any transfer |
A practical implementation checklist
- Map the data. Identify every field that is personal data of a person in Vietnam: names, phone numbers, national IDs, address, device identifiers, payment details.
- Draw the flows. For each field, note where it is written, where it is replicated to, and where backups land. Any flow that crosses the border is a PDPL transfer event.
- Choose the local anchor. Stand up the primary store on a Vietnam-located VPS or server, sized to your working set. 4 to 8 GB RAM handles most regional SaaS workloads; database-heavy systems want dedicated NVMe.
- Document the transfer. For anything that still leaves Vietnam, record the legal basis and the safeguards on the receiving side.
- Keep the runbook. If a Decree 53 request ever arrives, you should be able to answer "where is this data" in minutes, not weeks.
None of this requires a full rebuild if you plan it as a data-tier decision: keep the personal-data store in Vietnam, keep the stateless application where it is, and let the compliance boundary follow the data rather than the whole stack.
Common mistakes foreign firms make
- Assuming "no local entity" means "no obligation." The PDPL reaches foreign processors directly.
- Treating backups as exempt. A backup sitting in a foreign region is still a cross-border transfer of the same personal data.
- Confusing Decree 53 with a general localization mandate. It is a targeted mechanism, which means the risk is concentrated, not universal.
- Copying the marketing site's region choice into the data tier. CDN edge and database primary are different decisions.
Troubleshooting and edge cases
Legal says the data must stay, engineering says latency is fine either way. Put the personal-data store in Vietnam and keep read replicas abroad only for non-personal aggregates. Confirm with counsel before you call anything anonymised.
You already hold Vietnamese user data in a foreign region. Migrate the personal-data subset first, document the old store as a legacy transfer with a defined deletion schedule, and stop writing new personal data overseas.
You need to prove the data never left. Keep local snapshots, log the rDNS and IP of the node, and retain your impact assessment alongside the infrastructure records. If a request arrives, these are the artefacts that answer it.
FAQ
Does Decree 53 require every foreign firm to store data in Vietnam?
No. Decree 53 is enforced through a formal request aimed at a specific provider after a process. Many foreign firms never receive one. It is a risk to plan for, not a universal mandate.
Does the PDPL apply to my company if I have no Vietnamese entity?
Yes. The PDPL covers organisations processing personal data of individuals in Vietnam regardless of where the company is registered. Holding a local entity does not decide whether it applies.
Can I keep using a foreign cloud region for Vietnamese users?
You can, but the transfer must meet the PDPL's cross-border conditions and be documented. Many firms instead keep the personal-data store inside Vietnam to simplify that paperwork.
What infrastructure do I need to be compliant?
A server physically located in Vietnam with storage you control: NVMe disks, full root or Administrator access, and snapshot and backup capability. A local VPS or dedicated server covers most cases.
How long do I have to comply once a request arrives?
Decree 53 requests come with a compliance period set out in the notification rather than a fixed public number. Assume weeks, not years, and prepare your data map before anything arrives.
Is colocation better than a VPS for this?
Only if you already own hardware or have workloads too large for a VPS. For most compliant data stores, a local VPS or dedicated server is faster to deploy and easier to re-provision.
Related articles
- Vietnam Decree 53 data localization rules for SaaS
- Does Decree 53 require my company to host data in Vietnam
- What happens after A05 issues a written storage request
- Do you need a Vietnamese entity to buy hosting in Vietnam
越南数据本地化:第53号法令与PDPL合规要点
越南的数据本地化由两套不同规则构成:第53号法令是在执法程序后要求服务商在越南存储特定数据并设立本地机构,属于被触发式义务;《个人数据保护法》(PDPL)则从第一天起就适用于处理越南境内个人数据的外国企业,跨境传输必须满足条件并有记录。对多数面向越南用户的SaaS和电商企业来说,最稳妥的做法是把个人数据主库放在越南境内的服务器上,例如带NVMe、独立IPv4和完整root权限的越南VPS或独立服务器,只把非个人数据的分析留在境外。同时应建立数据映射与迁移预案,以便收到正式要求时能迅速响应。


