Law note · Vietnam
Law on Personal Data Protection, cross-border transfer
What it requires
- An app transferring the personal data of an individual in Vietnam, including biometric data, to a recipient outside the country must satisfy Article 20's cross-border transfer conditions; a violation risks a fine of up to 5 percent of the organization's prior-year revenue, a materially higher tier than the Law's general penalty.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
What we found
Article 20 enumerates the cases in which cross-border transfer of personal data is permitted; its substantive conditions, including any adequacy standard, government approval requirement, or data-localization element, were not read beyond the article's heading and opening clause this pass.
A separate penalties article confirms a materially strict enforcement posture: the maximum fine for an organization violating cross-border transfer regulations specifically is 5 percent of the organization's prior-year revenue, distinct from and higher than the Law's general violation fine tier.
Primary source
Government Portal (chinhphu.vn) citation
substantive text read via a private secondary translation (LuatVietnam)