In the context of digital transformation, data is playing an increasingly important role in business operations and the functioning of the economy. As digital platforms and cross-border services continue to expand, the collection, processing and storage of data in cyberspace have given rise to increasingly stringent requirements for information security and cybersecurity. In Vietnam, these requirements have been progressively developed and strengthened through the Law on Cyberinformation Security No. 86/2015/QH13 (the “2015 Cyberinformation Security Law”), the Law on Cybersecurity No. 24/2018/QH14 (the “2018 Cybersecurity Law”), and the Law on Cybersecurity No. 116/2025/QH15 (the “2025 Cybersecurity Law”), together with their implementing regulations.
The 2018 Cybersecurity Law introduced requirements for the storage of certain types of data in Vietnam and imposed an obligation on foreign enterprises to establish a branch or representative office in Vietnam in certain circumstances; these requirements are further guided by Decree No. 53/2022/ND-CP. On this basis, the 2025 Cybersecurity Law continues to retain the requirements on data storage in Vietnam and the obligation to establish a branch or representative office for foreign enterprises falling within its scope of application.
The following article provides an overview of certain regulations and key issues that businesses should note regarding the obligation to store data in Vietnam under the 2025 Cybersecurity Law.

1. Data Storage Obligations
Entities Subject to the Data Storage Obligation
Under the 2025 Cybersecurity Law, the data storage obligation applies to both domestic and foreign enterprises providing services over telecommunications networks, the Internet, and value-added services in cyberspace in Vietnam . This is a point worth noting, as the scope of entities subject to this obligation is not limited to enterprises established and operating under Vietnamese law, but also includes foreign enterprises providing services to users in Vietnam.
Types of Data Required to Be Stored
The types of data that domestic and foreign enterprises providing services over telecommunications networks, the Internet, and value-added services in cyberspace in Vietnam are required to store include:
- Data relating to the personal information of service users.
- Data generated by service users, including account names, service usage periods, service fee payment information, access IP addresses, and other relevant data for the most recent period after the user ceases to use the service.
- System logs recording the blocking of information sharing, deletion of information, and removal of services or applications containing content that violates the Cybersecurity Law.
Data Storage Location and Form
Except for data that is subject to the data storage requirement in Vietnam as discussed in this article, other data may be stored at a location and in a form selected by the enterprise based on its needs, provided that the data remains accessible and can be promptly retrieved and provided to the competent authorities upon request, and that such storage complies with the Law on Personal Data Protection and other relevant regulations.
Responsibilities of Data-Storing Entities
Domestic and foreign enterprises providing services over telecommunications networks and the Internet are responsible for:
- Providing user information to the specialised cybersecurity protection force under the Ministry of Public Security no later than 24 hours from the time a request is made in writing, by email, telephone, or another form of communication that has been verified, for the purposes of verifying, investigating and handling acts that violate cybersecurity laws. In urgent cases involving a threat to national security or human life, the requested information must be provided no later than 3 hours;
- Maintaining system logs recording the blocking of information sharing, deletion of information, and removal of services or applications containing content that violates the Cybersecurity Law, for the purposes of verifying, investigating and handling acts that violate cybersecurity laws, for the period prescribed by law.
2. Obligation to Store Data in Vietnam
Not in all cases may enterprises providing services over telecommunications networks, the Internet, and value-added services in cyberspace in Vietnam choose to store their data overseas. For certain types of data, entities that meet certain criteria are required to store such data in Vietnam. Specifically, as follows:
Entities Subject to the Obligation to Store Data in Vietnam
Vietnamese Enterprises
Vietnamese enterprises are required to store the types of data prescribed by law in Vietnam when they satisfy the following two conditions :
- The enterprise provides services over telecommunications networks, the Internet, or value-added services in cyberspace in Vietnam; and
- The enterprise collects, exploits, analyses, or processes data relating to personal information, data relating to the relationships of service users, and data generated by service users in Vietnam.
Foreign Enterprises
At present, the 2018 Cybersecurity Law and Decree No. 53/2022/ND-CP guiding the implementation of the 2018 Cybersecurity Law have ceased to be effective. Decree No. 333/2026/ND-CP guiding the implementation of the 2025 Law on Cybersecurity was recently issued on 19 August 2026 (“Decree No. 333/2026/ND-CP”). Article 19.3 (a) of Decree No. 333/2026/ND-CP specifically sets out the criteria under which a foreign enterprise is required to store data in Vietnam. Specifically:
(i) The foreign enterprise conducts business activities in Vietnam in one of the following sectors:
- Telecommunications services;
- Data storage and sharing in cyberspace;
- Provision of national or international domain names to service users in Vietnam;
- E-commerce;
- Online payment services;
- Payment intermediary services;
- Cyber-based transport connection services;
- Social networks and social media;
- Online games;
- Online applications; or
- Services for providing, managing or operating other information in cyberspace in the form of messages, voice calls, video calls, emails, or online chats.
(ii) The services provided by the enterprise are used to carry out acts that violate cybersecurity laws; and
(iii) The foreign enterprise has been notified by the Department of Cybersecurity and Hi-tech Crime Prevention under the Ministry of Public Security and requested to coordinate in preventing, investigating and handling such acts in writing on three occasions over a maximum period of 6 months, but fails to implement remedial measures, fails to comply, fails to fully comply, or prevents, obstructs, disables or renders ineffective the cybersecurity protection measures implemented by the specialised cybersecurity protection force.
Accordingly, when all three of the above criteria are satisfied, a foreign enterprise is required to store the relevant types of data and establish a representative office/branch in Vietnam as required by the competent authority.
Types of Data Required to Be Stored in Vietnam
Article 19.1 of Decree No. 333/2026/ND-CP provides for the types of data required to be stored in Vietnam, which are substantively similar to those specified in Article 26.1 of Decree No. 53/2022/ND-CP. Specifically, the types of data required to be stored in Vietnam include:
- Data relating to the personal information of service users.
- Data generated by service users in Vietnam, including the service account name, service usage period, credit card information, email address, IP address of the most recent login and logout, and the registered telephone number linked to the account or data.
- Data relating to the relationships of service users in Vietnam, including friends and groups with which the user connects or interacts.
Data Storage Method
Previously, under Article 26.5 of Decree No. 53/2022/ND-CP, the method of data storage was determined by the enterprise. However, Decree No. 333/2026/ND-introduces certain amendments and additions. Specifically, under Article 19.5 of Decree No. 333/2026/ND-CP, the method of storing data in Vietnam is determined by the enterprise, provided that the data remains accessible and can be promptly provided upon request by the competent authority, and that information security is ensured in accordance with national technical standards and regulations.
Accordingly, although enterprises remain free to determine the data storage method that is appropriate for their operations, the selected method must ensure that the data can be accessed and promptly provided upon request by the competent authority, while also complying with national technical standards and regulations on information security. Failure to satisfy these requirements may result in the enterprise being subject to sanctions in accordance with applicable laws, depending on the nature and severity of the violation.
Data Retention Period
Under Article 20 of Decree No. 333/2026/ND-CP and Article 27.1 of Decree No. 53/2022/ND-CP, the retention period for the relevant types of data is determined as follows:
At least 24 months from the date of receipt of the data retention request:
- Data relating to the personal information of service users in Vietnam.
- Data generated by service users in Vietnam, including the service account name, service usage period, credit card information, email address, IP address of the most recent login and logout, and the registered telephone number linked to the account or data.
- Data relating to the relationships of service users in Vietnam, including friends and groups with which the user connects or interacts.
At least 12 months: System logs recording the blocking of information sharing, deletion of information, and removal of services or applications containing content that violates the Cybersecurity Law, for the purposes of investigating and handling violations of the law.
3. Establishment of a Branch/Representative Office in Vietnam by Foreign Enterprises
Procedure for Competent Authorities to Require Foreign Enterprises to Store Data and Establish a Branch or Representative Office in Vietnam
As mentioned above, foreign enterprises that satisfy the three criteria under Article 19.3 (a) of Decree No. 333/2026/ND-CP are required to store data and establish a branch/representative office in Vietnam upon the request of the competent authority. The procedure for the competent authority to request data storage and the establishment of a branch or representative office is as follows:
Step 1: The Minister of Public Security issues a decision requiring the foreign enterprise to store data and establish a branch or representative office in Vietnam.
Step 2: The specialized cybersecurity force under the Ministry of Public Security shall notify, provide guidance to, monitor, supervise, and urge the enterprise to comply with the requirements for data storage and the establishment of a branch or representative office in Vietnam; and concurrently notify relevant authorities to perform their state management functions within their respective jurisdictions.
Step 3: Within 12 months from the date on which the Minister of Public Security issues the decision, foreign enterprises that satisfy all three criteria above must complete the data storage requirements and establish a branch or representative office in Vietnam.
Procedures for Establishing a Branch or Representative Office in Vietnam for Data Storage
The procedures for establishing a branch or representative office of a foreign enterprise in Vietnam shall be carried out in accordance with the laws on business, commerce, enterprises and other relevant regulations. Currently, the establishment of a branch or representative office of a foreign trader is governed by Decree No. 07/2016/ND-CP, which provides detailed regulations on the establishment of representative offices and branches of foreign traders in Vietnam, as amended and supplemented by Decree No. 146/2025/ND-CP.
Duration for Maintaining a Branch or Representative Office in Vietnam for Data Storage
The period during which a foreign enterprise that satisfies the three criteria above is required to maintain a branch or representative office in Vietnam commences from the date on which the enterprise receives the request to establish a branch or representative office in Vietnam and continues until the enterprise ceases its operations in Vietnam or the relevant services are no longer provided in Vietnam.
4. Conclusion
Overall, the provisions on data storage obligations under the 2025 Cybersecurity Law require enterprises to proactively review the types of data they collect and process, as well as their data storage methods, in order to properly fulfil their responsibilities. In particular, even foreign enterprises that are not yet subject to the requirement to store data in Vietnam must ensure that the relevant data can be accessed and provided to the competent authority within a very short period: no later than 24 hours from receipt of the request, and within only 3 hours in urgent cases.
Hence, enterprises should conduct a comprehensive assessment of the types of data collected, the location and method of data storage, the ability to retrieve and the timeframe for providing data, as well as their compliance arrangements in the event that a requirement to store data in Vietnam arises. Proactively reviewing and establishing appropriate mechanisms for data storage and provision will help enterprises mitigate the risk of non-compliance and ensure their ability to comply with the new cybersecurity requirements.
About the Author & Ecosystem: The article is legally supported by CDLAF and by the expertise of CFT Solutions – a company specializing in Finance – Tax – Accounting. We provide comprehensive management solutions that help enterprises control risks and optimize resources.
📩 BOOK A CONSULTATION WITH CDLAF’S LEGAL TEAM
Do not let procedural errors disrupt your business plans. Contact CDLAF today to receive a preliminary risk assessment from our team of Lawyers and E-commerce Legal Experts:
Hotline/Zalo: [+84 909 668 216]
Email: info@cdlaf.vn

Why choose CDLAF’s service?
- We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
- We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
- Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
- As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
- CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
- Strict information security procedures throughout the service performance and even after the service is completed.
You can refer for more information:
- Transferring Employees to Perform Other Works: Key Considerations for Enterprises
- Lawful Labor Discipline: Procedures and Key Notes for Enterprises
- Non-Compete Agreements In Employment Relationships: Are They Enforceable In Vietnam?
- Determining “Serious Damage” in Disciplinary Dismissal
- What Must Social Networks and Online Platforms Do to Comply with the Personal Data Protection Law 2025?
