Vietnam Decree 53 data localization compliance for foreign businesses

The question I get most from foreign teams running services in Vietnam is no longer "which VPS should I rent", it is "do we now have to store our data in Vietnam, and what happens if we do not". That shift started when Decree 53/2022/ND-CP went into force in late 2022, and it becomes sharper on July 1, 2026, when the new Law on Cybersecurity No. 116/2025/QH15 and the Personal Data Protection Law take over and tighten the same obligations. This post walks through what Vietnam Decree 53 data localization actually requires, which foreign businesses are caught by it, and the concrete ways to comply without guessing.
Key takeaways
- The localization duty under Decree 53 applies only to specific cybersecurity-relevant service categories, not to every company with users in Vietnam.
- Once triggered, the rules cover personal data, user relationship data, and Vietnamese user data, with both a 24-month in-country storage requirement and a 24-hour data handover obligation.
- From July 1, 2026, the Law on Cybersecurity 116/2025/QH15 and the Personal Data Protection Law (PDPL) replace and extend the old regime, so compliance efforts built now should target the 2026 baseline.
- Meeting the storage requirement practically means running infrastructure inside Vietnam, for example on a Linux VPS or a dedicated server in a local datacenter, not just signing a cloud agreement.
What exactly is Decree 53 and why it matters now
Decree 53/2022/ND-CP is the implementing regulation of Vietnam Law on Cybersecurity 24/2018/QH24. It is the document that turned the law's broad wording into concrete duties for foreign companies. The most cited provision is Article 26, which requires certain service providers to store data in Vietnam and to set up a local branch or representative office.
Two things make this relevant in 2026. First, the data localization obligation is not a distant legal possibility, it has been law since October 1, 2022. Second, the regime is being rebuilt: on July 1, 2026, the Law on Cybersecurity 116/2025/QH15 and the PDPL replace the 2018 law and Decree 53's data-related mechanics. Vietnam Decree 53 data localization compliance in practice therefore means understanding the current trigger conditions and the directions in which they are expanding.
第53号法令要求特定外资企业在越南境内存储数据并设立分支机构。
Decree 53 requires certain foreign service providers to store data inside Vietnam and to set up a local branch or representative office.
Which foreign businesses does Decree 53 apply to
This is the part most articles get wrong. The localization requirement does not apply to every foreign company that has Vietnamese users. Article 26 limits it to service providers in a defined list of sectors, and the obligation only triggers when one of those services is provided over telecom networks, the internet, or cyberspace in Vietnam and collects data from Vietnamese users. The listed sectors are telecommunications, data storage and sharing, provision of national and international domains, online content, e-commerce, online payments and intermediaries, social networks and messaging, and online computer gaming.
If your company is a software vendor selling B2B tools to Vietnamese firms but you are not operating a social network, an e-commerce platform, a payment intermediary, or one of the other listed categories, you are likely outside the core scope. That said, the 2026 reforms widen the practical obligations. The PDPL introduces notification and consent duties for any organization processing personal data of Vietnamese users regardless of sector, and the Law on Cybersecurity 116/2025 expands the categories of data that are considered sensitive. So the honest answer in 2026 is: the hard localization rule still targets a defined list, but the surrounding compliance floor now touches a much broader set of foreign businesses.
How to tell if the data localization trigger applies to your operation
Ask three questions in order. First, do you provide one of the services listed in Article 26 of Decree 53? Second, is that service delivered over the internet or telecom networks into Vietnam? Third, do you collect personal data, user relationship data, or data created by Vietnamese users? If you answer yes to all three, the localization duty applies to you today.
The category that catches the most foreign companies in practice is online content and social networks. If you run a platform where Vietnamese users create or share content, the obligation is hard to argue away. If you run an e-commerce site aimed at Vietnam, you are also clearly in scope. If you are an infrastructure or backend provider that merely stores data for other companies, you fall under the data storage and sharing category and carry your own obligations. When in doubt, treat the trigger as active and build compliance on that assumption.
What data must stay inside Vietnam
When the localization duty applies, three categories of data must be stored in Vietnam. The first is personal data related to Vietnamese users. The second is data on user relationships, meaning social relationships between users on your platform. The third covers data that users in Vietnam create, which includes content, communications, and any other user-generated material.
The 2026 baseline goes further. The PDPL classifies sensitive personal data as a distinct category, and the Law on Cybersecurity 116/2025 broadens the definition of data subject to protection. If you are rebuilding your storage architecture now, design it around the 2026 definitions, not the 2022 wording, so you do not have to restructure twice. Storage must be on infrastructure physically located in Vietnam, and it is worth confirming where your cloud provider's Vietnamese region actually stores data before assuming it meets the requirement.
What the 24-month storage and 24-hour handover rules require
Two time-based obligations sit at the core of Vietnam Decree 53 data localization compliance. The storage duty, under Article 26.3, requires in-country storage for a minimum of 24 months, and this period must be continuous, not reset by moving data out and back in. For a foreign company, that means your Vietnamese environment is not a cache, it is a persistent residency zone.
The second obligation is the data handover duty. When a Vietnamese competent authority makes a written request, you must hand over the data and information within 24 hours. This is fast, and it has real operational consequences. You cannot respond to a written storage request if your engineers do not know where the data lives, who can export it, and how long that export takes. Your compliance setup should include a documented procedure that can identify, extract, and deliver the requested data well inside the 24-hour window, not a vague intention to cooperate. If you want to understand how this process works in practice, this post on what happens after A05 issues a written storage request walks through the sequence.
Practical compliance paths for foreign businesses in 2026
There are three realistic ways to meet the storage requirement, and they differ in cost and control. The first is running your own infrastructure inside Vietnam, which is the cleanest option for companies that need direct control over their storage layer. This is exactly what a rent Linux VPS with a Vietnam IPv4 or a dedicated server in a Vietnamese datacenter gives you: data physically in country, under your own administration. If your workload is containerized, a VPS with enough RAM for multiple n8n workflows or Docker workloads keeps the entire stack local.
The second path is working with a Vietnamese cloud or hosting provider that offers local regions. The catch is that most compliance regimes, including Vietnam's, look at where the data physically sits, not at what a contract says. You need the provider to give you a concrete answer about which datacenter holds your data, and you need that datacenter to be in Vietnam. The third path is a hybrid model: keep a copy of the required data in Vietnam while running the rest of your global operation elsewhere. This is common for large platforms, but it is also the most complex to audit, because you must prove that the in-country copy is complete, current, and accessible within the handover window.
合规存储最直接的方式是在越南本地部署服务器,例如租用越南数据中心内的 VPS 或独立服务器。
The most direct compliance path is running local infrastructure in Vietnam, such as renting a VPS or a dedicated server inside a Vietnamese datacenter.
How to verify your data is actually stored in Vietnam
Do not rely on a provider's marketing page. Verify where your infrastructure physically sits. Ask the provider for the specific datacenter location and check it against known Vietnamese facilities such as Viettel IDC or VNPT IDC, both of which are Tier 3 facilities. If you run a VPS or dedicated server, you can check the IP range and the reported geolocation of your Vietnam IPv4 address as a quick sanity check. More importantly, ask your provider whether your data plane, not just your control plane, is in Vietnam. Some international clouds route the management interface locally but store data elsewhere, which does not meet the requirement.
For your own servers, document the physical location of the hardware in your compliance records. If you later receive a written storage request, you can point to the exact datacenter, the rack, and the storage volume. That level of precision is what turns a legal obligation into a manageable operational task. If the request process is unfamiliar, read what happens after a written storage request is issued so your team knows the sequence before it happens, not after.
Frequently asked questions
Does Decree 53 apply to all foreign companies with users in Vietnam?
No. The localization duty in Article 26 applies only to service providers in listed sectors, including telecommunications, data storage and sharing, e-commerce, online payments, social networks, and online gaming, and only when they provide services over the internet or telecom networks in Vietnam and collect user data. Companies outside these categories face the PDPL's general obligations from 2026, but not the hard localization rule.
What data must be stored in Vietnam under Decree 53?
Three categories: personal data related to Vietnamese users, data on user relationships, and data created by Vietnamese users. Storage must be continuous for at least 24 months, and data must be handed over to Vietnamese authorities within 24 hours of a written request.
Is renting a Vietnam VPS enough to comply with Decree 53?
It is a solid foundation for the storage requirement, because data on a VPS with a Vietnam IPv4 physically sits in a local datacenter. Compliance also covers the branch or representative office requirement and the 24-hour data handover procedure, so the VPS solves the storage half and you still need the organizational half.
What changes on July 1, 2026 for data localization in Vietnam?
The Law on Cybersecurity No. 116/2025/QH15 and the Personal Data Protection Law take effect, replacing the 2018 cybersecurity law and the data-related mechanics of Decree 53. They broaden the categories of protected data and introduce notification and consent duties for any organization processing personal data of Vietnamese users, so the compliance floor widens beyond the sector-specific localization list.
Can I use an international cloud's Vietnam region to comply?
Possibly, but you need to verify that the data plane physically resides in Vietnam and that the provider can state the exact datacenter. A control plane in Vietnam with data elsewhere does not meet the requirement. If you cannot get that confirmation, local infrastructure such as a Vietnamese datacenter VPS is the safer option.
Related articles
- Does Decree 53 require my company to host data in Vietnam
- What happens after A05 issues a written storage request
- VPS for internal company data storage: a 2026 setup guide
越南第53号法令数据本地化合规要点
第53号法令要求特定外资企业将越南用户数据存储在越南境内至少24个月,并在接到书面请求后24小时内移交数据。2026年7月1日起,新的网络安全法和个人数据保护法将扩大适用范围。最直接的合规方式是租用越南数据中心内的VPS或独立服务器,确保数据物理存储在本地。建议外资企业立即审查自身业务是否属于法令列出的行业,并提前建立数据移交流程。


