Cross-border data transfer and processing is increasingly common in the context of intense digitalization. In order to ensure data security and comply with legal regulations, Decree 165/2025/ND-CP has issued an impact assessment procedure before data is transferred abroad.

To support businesses and organizations in carrying out this procedure, HM&P provides detailed guidance on the subjects of application, dossiers, implementation procedures and results of the procedures for assessing the impact of cross-border data transfer and processing in accordance with the regulations and requirements of current laws.
1. Overview of procedures for assessing the impact of cross-border data transfer and processing[1]
1.1. Requirements of the procedure
|
STT |
Category |
Content |
|
1 |
Subjects of administrative procedures |
Organizations and individuals wishing to transfer and process cross-border data |
|
2 |
Internal Record Location |
National Data Center or National Public Service Portal |
|
3 |
How to Apply |
Submit the application through 01 of the following 03 methods:
|
|
4 |
Profile Components |
(Made according to Form No. 02 issued together with Decree No. 165/2025/ND-CP);
|
|
5 |
Number of Records |
01 (one) set |
|
6 |
Implementing agencies |
National Data Center, Ministry of Public Security |
|
7 |
Time limit for processing dossiers |
10 days from the date of receipt of a complete and valid dossier; in case the dossier is complicated and needs to be verified and examined, it shall not exceed 15 days |
|
8 |
Fees and charges |
Not |
|
9 |
Result |
The competent authority shall send a notice of the result of the dossier of impact assessment of border data transfer and processing according to Form No. 03 issued together with Decree No. 165/2025/ND-CP. The result of the dossier may occur in 01 of the following 02 cases:
|
Other relevant documents are flexible but mandatory, in order to demonstrate the legality, transparency and security of data transfers. This part is specified in Clause 4, Article 12, Decree No. 165/2025/ND-CP to support competent agencies in verifying information.
This is not a clearly defined fixed list but supplementary documents, proving the main report according to the form 02 mentioned above at the request of the competent authority from time to time.
In accordance with the regulations and Report Form 02, we believe that specific documents that are required to be submitted may include copies (not notarized except in cases where verification is required) of the following documents:
|
Text type |
Specific content |
Detailed Inquiry |
Purpose |
|
Contract/Agreement with the data recipient |
A copy of the legally enforceable contract/agreement (signed between the transferor and the recipient). |
Must include: the purpose of the data transfer; scope, method and time of storage/processing; data protection measures (encryption, access control); commitment to delete/destroy data after expiration; Damages and dispute resolution provisions. Valid at least until the time of submission of the application. |
Demonstrate the legality and legality of the data transfer, avoiding the risk of abuse. |
|
Identification documents of the data transferor (organization) |
A copy of the decision on establishment of the enterprise; Business registration certificate; or equivalent documents (e.g. Foreign Investment License). |
Issued by a competent authority of Vietnam; is still valid. |
Authenticate the legal status of the transferor, ensuring compliance with Vietnamese law. |
|
Identification documents of the data transferor (individual) |
Copy of Citizen Identity Card; Passport; or other identification papers. |
Valid for at least 06 months from the date of submission of the application. |
Authenticate personal identities, avoid fraud. |
|
Identification documents of the data recipient (organization) |
A copy of the establishment decision; Certificate of Business Registration; or equivalent papers of foreign organizations. |
If it is in a foreign language, accompanied by a Vietnamese translation; proving the address and field of operation. |
Assess the reputation and data protection of the recipient (can be checked through international databases if necessary). |
|
Identification documents of the data recipient (individual) |
A copy of your passport or other personal identification document. |
Valid for at least 06 months from the date of submission of the application. |
Similar to the personal transferor, personal responsibility is guaranteed. |
2. Order and procedures for assessing impacts on cross-border data transfer and processing
The order and procedures for assessing the impact of data transfer and processing shall be carried out according to the following steps:
Step 1: Organizations and individuals prepare dossiers in accordance with law;
Step 2: Organizations and individuals submit dossiers to the agency that assesses the impact of cross-border data transfer and processing;
Step 3: Within 10 days from the date of receipt of a complete and valid dossier, the agency competent to appraise and assess the impact of cross-border data transfer and processing; in case of complexity, verification and inspection is required, it shall not exceed 15 days;
Step 4: After the appraisal exam, the competent authority sends a notice of appraisal results to the requesting organization or individual.

Diagram of procedures for assessment of impacts on cross-border data transfer and processing
3. Notes when carrying out procedures for assessing the impact of cross-border data transfer and processing
Notes to be considered when carrying out the procedures for assessing the impact of cross-border data transfer and processing:
- Prepare all documents in accordance with the prescribed form (Form No. 01a/01b and Form No. 02 issued together with Decree 165/2025/ND-CP) to avoid dossiers being required to be supplemented or the appraisal time is extended.
- Clearly define the type of data to be transferred, the scope of processing, the purpose, the location of storage, and data protection measures as these are the key contents of the impact assessment report.
- Check in advance the information security and safety conditions of the overseas data recipient, ensuring compliance with the standards required by Vietnamese law.
- Closely monitor the progress of processing dossiers through the National Public Service Portal or directly contact the National Data Center when necessary to promptly process feedback from the appraisal agency.
- Update changes in policies and professional guidelines of the Ministry of Public Security because regulations related to data security are regularly reviewed and adjusted according to practice.
- Only transfer data after receiving a notice of approval from the competent authority, avoiding violations of regulations and being handled according to the law.
- Keep adequate records for inspection, assessment or request to prove compliance during operation.
The procedure for assessing the impact of cross-border data transfer and processing is a mandatory requirement and plays an important role in ensuring data security as well as maintaining compliance of businesses and individuals in accordance with current laws. Understanding the composition of the dossier, the submission process and the settlement deadline not only helps to minimize legal risks but also facilitates the transparent, safe and efficient data transfer process in the business process of enterprises in Vietnam.
[1] Decision No. 6636/QD-BCA-C12 on the announcement of new administrative procedures promulgated in the field of data within the scope and function of state management of the Ministry of Public Security; Decree No. 165/2025/ND-CP;
