AI Assistant Online
DCOMPASS - Aim with Precision, Build with Trust
NEWS/RESEARCH

DOES A DATA CENTER OPERATOR HAVE TO CONDUCT A CROSS-BORDER PERSONAL DATA TRANSFER IMPACT ASSESSMENT?

The development of Cloud and Data Center models is creating increasingly complex data flows across multiple jurisdictions. A business may collect data in Singapore, Europe, or another country, and subsequently transfer such data to server systems or storage infrastructure located in Vietnam for storage, training, or processing purposes. Under these models, an important question for investors and Data Center operators is: If personal data is brought by a customer into a Data Center in Vietnam, is the Data Center operator required to independently prepare a Cross-Border Personal Data Transfer Impact Assessment dossier?

DOES A DATA CENTER OPERATOR HAVE TO CONDUCT A CROSS-BORDER PERSONAL DATA TRANSFER IMPACT ASSESSMENT?
DCOMPASS Editorial•2026-09-21
NEWS/RESEARCH
DOES A DATA CENTER OPERATOR HAVE TO CONDUCT A CROSS-BORDER PERSONAL DATA TRANSFER IMPACT ASSESSMENT?

The development of Cloud and Data Center models is creating increasingly complex data flows across multiple jurisdictions. A business may collect data in Singapore, Europe, or another country, and subsequently transfer such data to server systems or storage infrastructure located in Vietnam for storage, training, or processing purposes.


Under these models, an important question for investors and Data Center operators is: If personal data is brought by a customer into a Data Center in Vietnam, is the Data Center operator required to independently prepare a Cross-Border Personal Data Transfer Impact Assessment dossier?


1. Legal Regulations on Cross-Border Personal Data Transfers


Vietnamese law currently regulates cross-border personal data transfers primarily under the Law on Personal Data Protection 2025, Decree No. 356/2025/ND-CP, together with relevant provisions of the Law on Data 2024, Decree No. 165/2025/ND-CP, and the Law on Cybersecurity 2018. This legal framework establishes requirements for controlling cross-border data transfers while safeguarding the lawful rights and interests of data subjects, national interests, and data security.


A cross-border personal data transfer may generally be understood as the transfer of personal data collected in Vietnam to another country, or the use of systems, platforms, or services located outside the territory of Vietnam to process such personal data. This activity does not only include sending data files to a foreign partner. Storing data on overseas servers, using international software, or granting access from outside Vietnam to data systems located in Vietnam may also give rise to compliance obligations.


For cross-border personal data transfers, a Cross-Border Personal Data Transfer Impact Assessment dossier is one of the key compliance mechanisms. Under the Law on Personal Data Protection 2025, this dossier is, in principle, required to be prepared and submitted within 60 days from the date of the transfer, except in cases where the law provides an exemption from the impact assessment requirement. Decree No. 356/2025/ND-CP further specifies the required contents of the dossier and applicable exemptions.


In principle, determining whether an activity constitutes a cross-border personal data transfer should be assessed based on the actual flow of the data, the parties involved, and the manner in which the data is transmitted, stored, or processed. Therefore, the fact that personal data is stored in a system located in Vietnam does not, by itself, mean that all activities involving such data constitute a cross-border personal data transfer.


2. When Data Is Transferred into Vietnam, Who Is Responsible for the Transfer?


A business leasing Data Center infrastructure may collect data in various jurisdictions, such as Singapore, the EU, the United States, or Vietnam, and subsequently transfer such data to Vietnam for storage or processing at a Data Center. In this case, the customer using the Data Center services is generally the party that needs to proactively determine the origin of the data, the applicable legal framework, and the conditions applicable to the transfer of data into Vietnam. The customer also determines which data is introduced into the system, the purposes of processing, the receiving system, and whether the data will subsequently be transferred to a third country.


By contrast, the Data Center operator merely provides the infrastructure on which the data is stored or processed and does not automatically become the party responsible for the legality of the data transfer carried out by the customer.


The fact that personal data is stored or processed on infrastructure located in Vietnam does not, by itself, mean that the Data Center operator should be regarded as the party carrying out a cross-border personal data transfer. Responsibility for a cross-border personal data transfer should be determined based on each party’s role, decision-making authority, and actual activities in relation to the data. Accordingly, the responsibilities of a Data Center operator may vary depending on the scope of services provided and the extent to which the operator participates in the processing or transmission of data. Specifically:

  • Where the Data Center operator only provides Colocation/infrastructure services, while the customer manages its own systems and independently carries out the data transfer, compliance responsibilities relating to the transfer will, in principle, rest with the customer to the extent required by applicable law.

  • Where the Data Center operator provides services such as system administration, backup, disaster recovery, or directly carries out the transmission of data overseas, the operator’s role and obligations should be reassessed based on its actual activities under Vietnam’s personal data protection regulations.


3. Scope of Responsibilities of a Data Center Operator


The fact that a Data Center operator is not the primary party responsible for classifying data or assessing the legality of the customer’s data processing and transfer activities does not mean that the operator has no responsibilities. Within the scope of the services provided, the operator should ensure infrastructure safety and security, control access rights, record and trace activities within the system, and appropriately segregate resources and data processing environments in accordance with the applicable service model. In particular, for cloud computing services or system administration services, maintaining system logs, audit logs, and access control mechanisms helps identify access rights, activities performed on the system, and the respective scope of control of each party.


At the same time, where a customer needs to prepare an impact assessment dossier or demonstrate compliance with personal data protection regulations, the Data Center operator may provide technical information within its management and control scope, including:

  • Data Center location;

  • Scope and architecture of the infrastructure;

  • Network connectivity;

  • Access control mechanisms;

  • Security measures;

  • System logs and traceability information;

  • Location of backup systems and disaster recovery systems;

  • Other relevant safety and security standards and certifications.


The Data Center operator is not necessarily required to prepare the impact assessment dossier on behalf of the customer. However, the operator should be capable of providing technical information and supporting evidence within its control to assist the customer in fulfilling its compliance obligations.


In conclusion, determining whether a Data Center operator is required to conduct a Cross-Border Personal Data Transfer Impact Assessment does not depend solely on whether the data is stored or processed at a Data Center in Vietnam. Rather, the assessment should take into account the operator’s role, scope of services, and actual level of involvement in the processing and transfer of data.


With its ecosystem of Data Center services and infrastructure solutions in Vietnam, DCOMPASS supports businesses in selecting appropriate Data Center models, designing service scopes, allocating responsibilities among relevant parties, and developing operational solutions that are aligned with data security and personal data protection requirements. If your business is considering deploying, leasing, or expanding a Data Center system in Vietnam, DCOMPASS can support you throughout the process — from advising on the appropriate model and selecting infrastructure to implementation and operation.

Share & Reading Tools

AI Intelligence Assistant

Ask questions directly about this article

SPECIAL REPORT

Vietnam Data Center Market Report 2026

Complete analysis of PDP8 power grid, DPPA mechanism, and 25+ high-capacity sites.

Get Report & Advisory

Send us a Message

Directly connected to DCOMPASS Operations Center