Personal Data Transfer under the 2025 Personal Data Protection Law: What Businesses Need to Know

Before the enactment of the 2025 Personal Data Protection Law, businesses—particularly parent-subsidiary groups and multinational corporations—frequently engaged in the movement of employees’, business partners’, and customers’ personal data for management and operational purposes. However, whether such movement of data constitutes a “personal data transfer” subject to personal data protection regulations remains an issue that many businesses have yet to clearly understand. In practice, we have observed that a considerable number of enterprises are unable to distinguish between the mere movement of data and a personal data transfer activity governed by personal data protection laws.

In this article, CDLAF provides a comprehensive overview of the legal issues arising from personal data transfers between enterprises and the key compliance requirements that businesses should be aware of.

Source: pexels-markus-winkler-1430818-30965505

1. Cases Where Personal Data Transfers Are Permitted

Vietnamese law does not absolutely prohibit the transfer of personal data. However, such activities may only be carried out in specific circumstances prescribed by law. Accordingly, organizations and individuals are permitted to transfer personal data in the following cases:

  • Where the lawful consent of the data subject has been obtained;
  • Where data is shared among departments within the same agency or organization for the purpose of carrying out data processing activities consistent with the purposes previously notified to the data subject;
  • Where the transfer of data is necessary to continue data processing activities in connection with the division, separation, merger, consolidation, restructuring, or conversion of the ownership structure of an enterprise;
  • Where a personal data controller or a personal data controller-cum-processor transfers data to a personal data processor or a third party for the purpose of conducting data processing activities in accordance with the law;
  • Where required by a competent state authority in accordance with applicable laws; or
  • In cases where personal data may be processed without the consent of the data subject as prescribed by law.

The fact that the law permits personal data transfers in certain circumstances does not mean that businesses are free to share personal data with third parties without restriction. In practice, each type of transfer is subject to its own conditions, responsibilities, and compliance requirements. Therefore, before transferring personal data, businesses should clearly identify the applicable legal basis, the roles of the parties involved in the data processing activities, and the purpose of the transfer. These factors serve as the foundation for demonstrating the lawfulness of the data processing activity and mitigating legal risks during business operations.

2. Personal Data Transfer Does Not Mean the Sale or Purchase of Personal Data

One of the notable features of the current legal framework is the clear distinction between the lawful transfer of personal data and the sale or purchase of personal data.

Accordingly, the transfer of personal data in circumstances permitted by law, regardless of whether a fee is charged, is not regarded as the sale or purchase of personal data. This distinction is particularly significant for businesses whose business models rely on outsourcing arrangements, technology platforms, or cooperation with business partners for the processing of personal data.

Nevertheless, for a transfer to be considered lawful, it must fully satisfy the legal requirements, including the existence of a clear legal basis for the transfer, a lawful purpose for data processing, a proper allocation of the roles and responsibilities of the relevant parties, and adequate protection of the rights of personal data subjects. Any attempt to use the concept of “data transfer” as a means to exchange, trade, or exploit personal data beyond the scope permitted by law may be regarded as a violation of the applicable data protection regulations.

In practice, many businesses question whether sharing data with a parent company, technology service provider, customer care provider, or advertising agency could be considered the sale or purchase of personal data. The answer does not depend on whether any payment is involved, but rather on the nature and substance of the transaction.

If personal data is transferred for a legitimate data processing activity, for a lawful and specified purpose, on the basis of a clear legal ground, and with appropriate safeguards for personal data protection, such activity may be regarded as a lawful personal data transfer. Conversely, where personal data becomes a form of “commodity” that is exchanged or exploited for commercial purposes beyond the scope permitted by law or beyond the consent granted by the data subject, the business may face significant legal risks.

3. What Should a Personal Data Transfer Agreement Include?

In certain cases of personal data transfer as prescribed by law, the organization or individual transferring the data is required to enter into a personal data transfer agreement with the data recipient. This is not merely a procedural requirement but also serves as the legal basis for clearly allocating the rights, obligations, and responsibilities of the parties throughout the personal data processing life cycle.

According to the law, a personal data transfer agreement should include, at a minimum, the following contents:

  • The purpose of the personal data transfer;
  • The categories of personal data subjects and the types of personal data to be transferred, in line with the purpose of the transfer;
  • The period for processing personal data, together with clear requirements regarding the deletion or destruction of personal data upon completion of the transfer purpose;
  • The legal basis for the personal data transfer;
  • The responsibilities for protecting personal data during the transfer and processing activities;
  • The responsibilities for ensuring the exercise of the rights of personal data subjects; and
  • The responsibilities of the parties to cooperate and comply with applicable laws in the event that any violation of personal data protection regulations is identified.

In practice, the above requirements may be documented in a standalone personal data transfer agreement or incorporated as personal data protection clauses within commercial agreements or service contracts between the parties. Regardless of the form adopted, businesses should ensure that all mandatory legal requirements are fully and clearly documented.

One of the common issues that CDLAF has observed in the course of advising clients is that businesses often execute standard service agreements while overlooking specific provisions relating to personal data protection. As a result, when a data breach occurs or a request is made by a data subject, the parties may be unable to determine who acts as the data controller, who is responsible for handling the data subject’s request, who is responsible for notifying the relevant authorities and affected data subjects of a personal data breach, or who must delete the personal data upon termination of the contractual relationship.

Accordingly, businesses should not treat a personal data transfer agreement as a mere “formal appendix.” On the contrary, it is an important risk management tool that helps clarify the scope of each party’s responsibilities, strengthens the ability to demonstrate legal compliance, and significantly reduces the risk of disputes and regulatory sanctions arising from personal data incidents. As personal data protection requirements continue to become more stringent, standardizing data transfer provisions should be regarded as an indispensable component of a company’s legal and compliance governance framework.

4. Security Requirements for the Transfer of Sensitive Personal Data

Sensitive personal data is a category of data that may directly affect the lawful rights and interests of a data subject if disclosed or used unlawfully. Accordingly, the law imposes more stringent security requirements on the transfer of this type of data.

Under the applicable regulations, organizations and individuals transferring sensitive personal data must implement appropriate protective measures, including:

  • Physical security measures for devices used to store and transmit data;
  • Encryption measures for personal data during the transfer process;
  • De-identification or anonymization measures where appropriate; and
  • Other technical and organizational measures to ensure the security of personal data throughout the processing life cycle.

In practice, transmitting sensitive personal data through unencrypted emails, using uncontrolled personal storage devices, or sharing data through platforms that do not provide adequate information security safeguards may significantly increase the risk of data breaches and expose businesses to serious legal consequences.

5. Conditions for Fee-Based Personal Data Transfers

The law does not prohibit fee-based personal data transfers in certain circumstances where such transfers are carried out to provide services to data subjects or to serve their legitimate interests. However, to safeguard the rights and interests of data subjects, organizations and individuals engaging in such activities must simultaneously satisfy a number of stringent legal requirements.

Specifically, businesses must:

  • Establish technical systems and transparent mechanisms enabling data subjects to provide accurate and explicit consent for each instance of personal data transfer;
  • Ensure that data subjects are fully informed of the purpose of the transfer and the identity of the organizations or individuals receiving and processing their personal data;
  • Process personal data solely for the purposes consented to by the data subjects and disclosed to them in advance and in a manner consistent with the enterprise’s registered business lines;
  • Limit the categories of personal data transferred to those necessary for the intended processing purpose;
  • Refrain from collecting, storing, or creating personal data repositories from transfer activities for purposes other than those approved by the data subjects;
  • Clearly define the legal roles of the parties involved in the data processing activities, including the personal data controller, personal data processor, and third party; and
  • Establish a personal data transfer and processing agreement prior to the transfer and undertake full responsibility towards the data subjects.

It is evident that the law does not focus on whether a personal data transfer is conducted for a fee or free of charge. Rather, the key considerations are whether the transfer is transparent, carried out for a lawful and specified purpose, and adequately safeguards the rights of the data subjects.

6. How Should Internal Personal Data Sharing Be Controlled?

The law permits the sharing of personal data among departments within the same agency or organization for data processing activities that are consistent with the purposes previously established. However, businesses are responsible for establishing internal control procedures governing access to, use of, and sharing of personal data, while also implementing measures to prevent employees from unlawfully disclosing such data to third parties.

In practice, many personal data breaches do not result from external cyberattacks but originate from within the organization itself. Accordingly, access control mechanisms, audit log management, and employee training on personal data protection should be regarded as essential components of a robust compliance framework.

7. Personal Data Must Be De-Identified Before Being Traded on a Data Exchange Platform

Under the law, personal data must be de-identified before any transaction on a data exchange platform takes place. This requirement is intended to reduce the possibility of directly identifying a data subject and to minimize the risk of infringing upon individual privacy rights.

Businesses should note that merely removing a person’s name may not necessarily satisfy the legal requirement for de-identification. If the data can still be combined with other information to identify a specific individual, the business may continue to face legal risks associated with personal data protection.

8. Circumstances That Are Not Considered Personal Data Transfers

Not every act of providing data constitutes a personal data transfer under the law. Certain circumstances are expressly excluded, including:

  • Where a personal data controller provides personal data directly to the data subject upon the data subject’s lawful request; and
  • Where a personal data controller provides personal data to another agency, organization, or individual at the request and with the consent of the data subject, unless otherwise provided by law.

The distinction between the “provision of data at the request of the data subject” and a “personal data transfer” is significant in determining a business’s compliance obligations. Accordingly, before engaging in any data sharing activity, businesses should carefully assess the legal nature of the transaction in order to apply the appropriate compliance mechanism.

Personal data transfers are a common aspect of business operations, ranging from the engagement of service providers and intra-group data sharing to collaboration with business partners. However, they also represent one of the areas that may expose businesses to substantial legal risks if not properly managed.

From our practical advisory experience, CDLAF has observed that compliance with personal data transfer regulations extends far beyond merely obtaining the consent of the data subject. Businesses are also required to establish a comprehensive legal basis, develop appropriate internal procedures, and implement governance mechanisms tailored to each specific situation.

As personal data protection requirements continue to become more stringent, businesses that proactively standardize their data processing and data transfer practices will be better positioned to build trust with customers, employees, and business partners while significantly reducing long-term legal and regulatory risks.

Time of writing: June 09, 2026

The article contains general information which is of reference value. In case you want to receive legal opinions on issues you need clarification on, please get in touch with our Lawyer  at  info@cdlaf.vn

Why choose CDLAF’s service?

  • We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
  • We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
  • Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
  • As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
  • CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
  • Strict information security procedures throughout the service performance and even after the service is completed.

You can refer for more information:

    SEND CONSULTATION REQUEST