The legal framework governing the operation of Data Centers (DC) in Vietnam is built on the basis of basic laws on technology and telecommunications. Initially, the general rules on information technology application and development activities were established in the Law on Information Technology 2006. This law provides general principles, including the right to apply information technology in commerce and regulations on specialized inspections. In parallel, the Telecommunications Law 2023 sets out a framework for the management of telecommunications networks and services, including encouraging infrastructure development.

However, in the context of the rapid growth of digital infrastructure and the need for data protection, the legal framework is shifting from foundational documents to in-depth regulations, with more complex requirements. In this article, we will outline some specific difficulties that foreign-invested enterprises face when doing business in this field in Vietnam.
1. What are Data Center Services?
One of the most important points in the new legal framework is the classification of DC services. The Telecommunications Law 2023 has clearly defined a data center service as a type of "Telecommunications service that provides information processing, storage, and retrieval to users via telecommunications network by leasing part or all of the data center".[1]
The classification of DC as a telecommunications service brings far-reaching legal implications and strengthens State oversight. If DC is only considered a real estate service or a mere IT service, the legal requirements will be somewhat easier. However, when classified as telecommunications services, DC service providers are required to comply with telecommunications specialized business conditions. This includes strict requirements for licensing, legal capital, and service quality management, which are managed by the Ministry of Information and Communications (now the Ministry of Science and Technology). This establishes a higher barrier to market entry, especially for foreign investors.
DC's operations are governed by many State agencies, reflecting the interdisciplinary nature of this service. From the Ministry of Science and Technology is a specialized management agency in telecommunications, information technology, and cyber information security (ATT). This ministry is responsible for issuing specialized licenses and issuing technical standards for DC. Until the Ministry of Public Security, through the Department of Cyber Security and High-tech Crime Prevention and Control (A05), the Ministry of Public Security acted as a specialized agency in charge of protecting personal data. The Ministry of Public Security is also the agency in charge of appraisal of cybersecurity requirements and procedures related to cross-border data transfers. And finally, the Ministry of Finance (formerly the Ministry of Planning and Investment) is the agency responsible for issuing the Investment Registration Certificate (IRC), which is the first step for all foreign investment projects in the DC sector.
2. Requirements when doing business data center services in Vietnam
For foreign-invested DC projects, the legal process consists of many complex stages to ensure compliance with both the Law on Investment and specialized telecommunications industry regulations. In addition to ordinary investment documents such as Investment Registration Certificates, Enterprise Registration Certificates, investors must also carry out procedures to issue specialized licenses related to specific business activities and comply with post-licensing requirements.
Although the current legal documents do not provide a specific figure on the statutory capital of the DC service, the inclusion of DC in the telecommunications services group has implied that the financial and technical conditions will be very stringent. For example, other telecommunications services such as establishing terrestrial mobile networks without using radio frequency bands require legal capital of VND 300 billion and an investment commitment of up to VND 1,000 billion in the first 3 years[2]. The application of these equivalent or near-equivalent conditions to DC service providers imposes a significant financial and technical requirement, creates a financial barrier for small investors and forces large corporations to commit significant capital. This rigor reflects DC's strategic role in the nation's digital infrastructure.
In addition, foreign investors need to be aware of ownership restrictions. The Law on Investment 2020 allows the application of ownership limits for each specific industry. DC operations that serve nationally critical information infrastructure or involve government data will often be subject to additional scrutiny or restrictions. In some cases, foreign investors may be required to cooperate with domestic partners to mitigate national security risks.
Recently, on November 11, 2025, the Government proposed to review and cut 25 conditional business lines to switch to post-inspection, promoting business freedom, including the data center service business in Vietnam[3]. Perhaps in the coming time, this business will be more relaxed with the desire to attract more investors with the potential and ability to develop the digital data segment that is very necessary for Vietnam.
3. Requirements for information system security compliance and troubleshooting
The Government's Decree No. 85/2016/ND-CP is a core legal document regulating the security of information systems by level. This Decree classifies the information system into 5 levels based on its importance and impact if it breaks down. DCs, as data storage and processing facilities for many organizations, must define and disclose the level of security for the information systems that DCs store or operate.
The safety level requirement is particularly stringent for DCs that want to provide services to the State sector, e-government agencies, or national critical information systems. Practice has shown that the leading DCs in Vietnam have had to meet level 4 information system security standards. To achieve level 4, the DC system must be strictly set up, capable of serving the operation and providing services to customers in the public sector, where 24/7/365 operation is required, and absolutely does not accept unplanned operation stoppages. The due diligence to reach Level 4 consists of three main pillars: (1) Ensuring the continuity of the hardware infrastructure; (2) Comprehensive supervision policy and strict operation; and (3) Information security and management software according to international standards.
Below is a summary of information system security standards and their impact on DC operations:
|
ATHTTT Level |
Protection Objectives |
Core Operational Requirements |
Effects on DC |
|
Level 3 |
Important information of the agency/business. |
Strict control, physical and logical layer protection. |
DC needs to be achieved to store sensitive data of enterprise customers. |
|
Level 4 |
Top secret information, serving e-Government. |
Operate 24/7/365, do not accept unplanned operation stoppages. |
Required for DC to participate in the service supply chain for the State. |
|
Level 5 |
Top Secret National Security Information. |
Highest security requirements (Usually private networks). |
Less common, related to strategic core data infrastructure. |
In addition to meeting cybersecurity standards, DC providers have a legal obligation to build and maintain cybersecurity incident response capacity. The regulations require DCs to have a plan to assess cyber security risks and incidents and develop specific response and rescue plans[4]. This is necessary to ensure information security for critical information systems. DCs must strictly comply with reporting requirements, using standard templates specified in specialized circulars. Compliance with this process is not only a legal requirement but also a testament to the service provider's operational capacity.
4. Requirements for cross-border data storage and transfer
Firstly, businesses are required to store mandatory data
Cybersecurity regulations in Vietnam include mandatory data storage requirements for certain services in cyberspace. The list of regulated services includes data storage and sharing services in cyberspace, in addition to telecommunications, e-commerce, online payments, and social media services.
According to the Law on Cyber Security and its guiding decrees, enterprises providing data storage services on this list must store data of Vietnamese users in Vietnam upon written request from competent state agencies.
Data storage regulations in Vietnam pose a major challenge for cloud service providers and global DC providers, which often operate on a distributed storage model. To be compliant, DC providers must ensure they have physical infrastructure in Vietnam and have the ability to segregate Vietnamese user data for domestic storage on demand. This requires a commitment to large investments in infrastructure and transparency in data architecture.
Second, the process of transferring data across borders
The transfer of cross-border personal data is strictly regulated in Decree 13/2023/ND-CP and the Law on Personal Data Protection 2025 which is about to take effect. All cross-border data transfer activities must strictly comply with the principles of ensuring national defense and security, protecting national interests and public interests, as well as the legitimate rights and interests of data subjects.
The top mandatory requirement is that the organization performing the cross-border data transfer must conduct a Cross-Border Data Transfer Impact Assessment. This report is not only a legal obligation but also a risk management tool, helping businesses demonstrate that data transfers are carried out in a secure and responsible manner. The assessment dossier must be submitted to the Department of Cyber Security and High-tech Crime Prevention and Control (A05) under the Ministry of Public Security.
Notably, Vietnamese law classifies data transfers based on the sensitivity of the data, including: Important data and core data.
In addition, DC needs to proactively assess the capacity and reputation (Due Diligence) of any Third Party involved in the data processing process. This includes requesting proof of compliance, such as a copy of the personal data protection policy and cybersecurity certificates. This thorough due diligence helps to bind liability and minimize the risk of data leakage from the systems of relevant partners.

Inside the VNG Data Center. Source: VNG
5. Some recommendations for businesses operating in this field
To successfully operate DC in Vietnam's increasingly stringent regulatory environment, investors should take the following actions:
Investment strategy consulting: Foreign investors need to carefully study the applicable ownership limits and prepare a flexible financial plan to meet the legal capital conditions and large investment commitments in accordance with the provisions of the telecommunications law.
Proactive security upgrades: DC should aim to achieve a minimum level 4 security clearance, especially if the goal is to serve state, financial, or nationally critical infrastructure organizations. This is not only about compliance, but also about competitive advantage, proving the ability to operate continuously and reliably.
Strict data contract management: Establish transparent and detailed Data Processing Agreements (DPAs) with customers. The legal role to limit DC's liability under Decree 13/2023 (later the Personal Data Protection Law 2025) must be clearly defined and thorough due diligence must be carried out on any Third Parties involved.
The DC services market in Vietnam is facing great opportunities thanks to the growing demand for cloud services, the government's support for digital transformation initiatives, and Vietnam's strategic position in Southeast Asia. The government is working to promote the construction of a national database and database by 2030. aiming to bring Vietnam into the group of leading countries in e-Government and information technology[5]. However, along with this opportunity is the trend of increasingly tight legal management. The introduction of documents such as Decree 13/2023/ND-CP, the Telecommunications Law 2023, the Data Law 2024 and the Personal Data Protection Law 2025 shows that the legal framework is shifting from a technology-neutral management approach to a risk-based strict management approach. Particularly focusing on the control of personal data, ensuring the safety of information systems, and protecting national security. The success of foreign investors in the DC sector will depend on their ability to meet these high compliance standards and maintain close cooperation with Vietnam's State regulators.
Lawyer Nguyen Van Phuc
HM&P Law Firm
[1] Clause 9, Article 3 of the Law on Telecommunications 2023.
[2] Clause 3, Article 32 of Decree 163/2024/ND-CP.
[3] https://baochinhphu.vn/de-xuat-ra-soat-cat-giam-25-nganh-nghe-kinh-doanh-co-dieu-kien-102251111110855627.htm, accessed 11/11/2025.
[4] Article 19, Decree 85/2016/ND-CP
