Home What is Vantu Talent in Vietnam The Vantu Way Testimonials & FAQ Insights Contact Us
Back to Insights

GDPR and a Vietnam dev team: the data steps in order

Published · 7 min read

Person taking notes on a clipboard next to a laptop at a desk
Photo: Zulfugar Karimov, Unsplash

Vietnam is not on the European Commission's official list of adequacy decisions (checked on 1 October 2026). If your team there accesses personal data of European customers, you need a safeguard under Article 46 of the GDPR, usually standard contractual clauses. This article sets out the steps.

What it means that Vietnam has no adequacy decision

An adequacy decision is a Commission ruling that a country protects personal data adequately. With one, data can flow to that country without further steps (GDPR, Art. 45(1)). Without one, each transfer needs appropriate safeguards (Art. 44 and Art. 46(1)).

An international transfer means giving a recipient outside the EU access to personal data. The controller decides why and how the data is used (Art. 4(7)). The processor handles the data on the controller's behalf (Art. 4(8)).

Remote access is also a transfer

Many teams assume that if the servers stay in the EU, there is no transfer. The European Data Protection Board (EDPB) says otherwise in Guidelines 05/2021 (version 2.0, February 2023), section 2.2. Remote access from a third country, "even if it takes place only by means of displaying personal data on a screen", is a transfer.

Three criteria must all be met. The exporter is subject to the GDPR. It makes the data available to another controller or processor, the importer. The importer is in a third country.

An engineer in Ha Noi who opens a database hosted in the EU meets all three. If the team sees no personal data, there is no transfer of personal data.

Safeguards available when there is no adequacy decision

Standard contractual clauses

These are contract templates written by the Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (GDPR, Art. 46(2)(c)). There are versions for controller to processor and processor to processor transfers. You sign them and complete their annexes.

A small startup can close this route with its usual lawyer.

Binding corporate rules

These are internal data protection policies of a group of companies, approved by an authority (Art. 47). The Spanish authority, the AEPD, has approved those of groups such as Iberdrola and Prosegur. They apply to transfers inside one group.

If your startup and the Vietnamese partner are independent companies, they do not apply. Drafting and approval also do not suit a small company.

The Article 49 derogations

Article 49(1) allows transfers without safeguards in specific cases: explicit consent, performance of a contract, vital interests, public interest, legal claims and public registers. These are one-off situations.

A team that opens the repository every week is not a one-off situation. Use the standard clauses for continuous access.

The transfer impact assessment

It is a written analysis that answers one question: in Vietnam, can the recipient comply with the clauses? Clause 14 of the standard clauses requires assessing whether the laws and practices of the destination country could prevent it, according to the Commission's Q&A on the clauses (question 41).

The exporter, meaning the European controller, carries it out with information from the recipient. EDPB Recommendations 01/2020 (final version of 18 June 2021) help choose supplementary measures.

It has to look at four things:

  1. Which personal data is transferred and how sensitive it is.
  2. Who accesses it, from where and with which tools (VPN, remote desktop, local copy).
  3. Which Vietnamese laws let authorities request data from the recipient. PENDIENTE: local legal analysis, not included in this article.
  4. Which technical measures reduce the risk: minimum access, synthetic data in development, encryption and access logs.

Who is controller and who is processor in a setup like Vantu's

The European startup is usually the controller: it decides which customer data is processed and why (Art. 4(7)). Whoever provides the technical service on the startup's behalf acts as processor (Art. 4(8)). The test is who decides purposes and means, not who signs the payslips.

In Vantu's setup, a local partner signs the employment contract. That does not make the partner a controller. If its employees process data on instructions from the startup or from Vantu, the partner is a processor or sub-processor, depending on who gives the instructions.

Article 28 of the GDPR requires the processing to be governed by a contract between controller and processor. The whole chain needs to be in writing: startup, Vantu and local partner. PENDIENTE: confirm with Vantu which entity signs each link.

Data flow from a European customer: 1 end customer (data subject), 2 European startup (controller), 3 Vantu entity (processor), all in the European Union; 4 local partner and employer (processor or sub-processor, importer) and 5 engineers in Ha Noi or Ho Chi Minh with remote access, in Vietnam. The international transfer (Art. 44) happens at remote access, safeguarded by standard contractual clauses (Decision (EU) 2021/914, Art. 46(2)(c)) and a transfer impact assessment. If the team forwards data outside Vietnam, Vietnamese rules also apply.

Concrete obligations of the controller

Obligation Who meets it Document that proves it Legal basis
Govern the processing by contract Controller and processor Processor agreement GDPR, Art. 28
Choose a safeguard for the transfer Controller (exporter) and recipient in Vietnam Signed standard contractual clauses with annexes GDPR, Arts. 44, 46(1) and 46(2)(c); Decision (EU) 2021/914
Assess the transfer Exporter, with information from the recipient Transfer impact assessment report Clause 14 of the standard clauses; EDPB Recommendations 01/2020
Inform data subjects Controller Updated privacy notice GDPR, Arts. 13 and 14. PENDIENTE: exact paragraph
Record the processing Controller and processor Record of processing activities GDPR, Art. 30. PENDIENTE: verify text on EUR-Lex
Apply security measures Controller and processor Access policy and access logs GDPR, Art. 32. PENDIENTE: verify text on EUR-Lex
Comply with Vietnamese law Entity processing the data in Vietnam Impact assessment dossier and data protection officer, where applicable Law 91/2025/QH15 and Decree 356/2025/ND-CP. PENDIENTE: articles

What Vietnamese law requires

The law in force is Law 91/2025/QH15 on personal data protection, adopted on 26 June 2025 and effective from 1 January 2026. Its implementing decree is Decree 356/2025/ND-CP of 31 December 2025, also effective from 1 January 2026. It replaces Decree 13/2023/ND-CP, according to Rajah & Tann and LuatVietnam.

According to DLA Piper, organisations that process data must file an impact assessment dossier with the Ministry of Public Security (A05) within 60 days of starting to process. According to EY, small enterprises and startups have a five-year exemption from 1 January 2026, unless they process sensitive data or reach 100,000 data subjects.

None of these sources is the official text. PENDIENTE: open the law and the decree in the Vietnamese official gazette and confirm three points: whether they apply to EU citizens' data processed in Vietnam, who files the dossier, and whether an amendment is in progress.

What this article does not cover

It does not cover Vietnamese employment law, intellectual property in the code, taxation or onward transfers from Vietnam to other countries. It also does not analyse access to data by Vietnamese authorities, which a local lawyer must review.

Checklist

  1. List the personal data the team will see. Cut access to the minimum and use synthetic data in development.
  2. Write down who is controller, processor and sub-processor in the chain.
  3. Sign the processor agreement (Art. 28).
  4. Sign the standard contractual clauses with the recipient in Vietnam (Art. 46(2)(c)) and complete the annexes.
  5. Write the transfer impact assessment and apply the technical measures it produces.
  6. Update the privacy notice and the record of processing, and confirm with the local partner its filings in Vietnam.

FAQ

If my servers are in the EU, is there a transfer?

Yes. The EDPB treats remote access from a third country as a transfer, even if the data is only shown on screen (Guidelines 05/2021, section 2.2).

Explicit consent is one of the Article 49(1) derogations. It is an exception for one-off cases. For continuous access, the usual route is Article 46. Confirm it with your lawyer.

Does Vietnamese law also apply to me?

To the entity processing the data in Vietnam, probably yes: Law 91/2025/QH15 has been in force since 1 January 2026. Whether it applies to EU customer data is PENDIENTE, to be confirmed.

What if the team only sees code and no data?

Then there is no transfer of personal data for that part. Check that the repository holds no credentials, logs or test databases with real data.

This guide is general information, not legal advice, and each case should be reviewed with a lawyer.

First step

If your team in Vietnam already accesses the repository, start with step 1: list which personal data each person sees. Your lawyer can then close the contract and the clauses. Write to us and we will review the access setup.

Sources

All sources consulted on 1 October 2026.