NHÂN KIỆTSince 2009

Insights

Vietnam Cross-Border Data Transfer: EOR, PEO and Payroll

When the data of employees in Vietnam — payroll, timesheets, personnel files — is sent or made available to a company abroad, that is a cross-border transfer of personal data under Article 20(1) of the Law on Personal Data Protection No. 91/2025/QH15. The transferring party must prepare an impact assessment dossier and file it with the specialised personal data protection authority under the Ministry of Public Security within 60 days of the first transfer, unless an exemption applies. With EOR, PEO and outsourced payroll, the deciding question is who the transferring party is: the service provider, or your own company.

This article is written for foreign companies that employ staff in Vietnam through a provider, and for Vietnamese subsidiaries that report HR data to their group. Every provision cited comes from the original text of Law 91/2025/QH15 and Decree 356/2025/ND-CP, both in force since 1 January 2026.

When is employee data treated as transferred out of Vietnam?

Law 91/2025/QH15 treats three activities as cross-border transfers of personal data, and all three are common whenever HR has a foreign element:

Article 17 of Decree 356/2025/ND-CP restates these three cases and makes clear that they apply to every role — controller, processor and third party alike. In other words, a service provider that sends data abroad at a client's request is itself making a cross-border transfer.

If a foreign client only views data on a portal, is that still a transfer?

The prudent reading is yes. The law has no exemption for "view-only" access, and Article 2(6) of Law 91/2025/QH15 lists "providing" data as a form of processing. When someone abroad opens a payroll screen, the data travels to their device, so it can be regarded as provided to an organisation abroad.

That does not make a view-only approach worthless — quite the opposite. The impact assessment must describe how the data is kept secure after transfer, and the process by which the recipient passes data on to third parties (Article 18(3) of Decree 356/2025/ND-CP). When a client can only view data inside the transferring party's system, there are fewer copies, fewer leak points, and the transferring party can show it keeps control of the data end to end. View-only access does not remove the obligation, but it is the strongest way to meet it.

Who files the dossier under EOR, PEO or payroll outsourcing?

The dossier is filed by whoever makes the transfer abroad, and that depends on who the employer is. Under EOR, the provider is the employer and the party making the data available to the foreign client, so the provider files. Under PEO and payroll outsourcing, your Vietnamese entity is the employer; when that entity shares data with its parent company, the obligation sits with that entity.

ModelEmployerProvider's data roleWho transfers data abroad
EORThe EOR providerController-processorThe provider, when it makes data available to the foreign client
PEOThe client's Vietnamese entityProcessorThe Vietnamese entity, when it shares data with the parent company
Payroll outsourcingThe client companyProcessorThe client company, when it shares data with the parent company

The cleanest split for PEO and payroll: the provider delivers reports to your Vietnamese entity, and forwarding them to the group is the employer's decision — and the employer's dossier. If you ask the provider to send reports straight to the parent company, the provider also becomes a transferring party and must be named in the dossier. The full difference between the two models is covered in EOR vs PEO in Vietnam.

Are transfers to a parent company exempt from the impact assessment?

They can be, if the transfer serves cross-border personnel management under labour rules, internal labour regulations and collective labour agreements. This is a new exemption in Article 17(3)(d) of Decree 356/2025/ND-CP, written for groups that manage staff in several countries.

The condition is in the wording itself: the sharing must follow the employer's labour rules, internal labour regulations and collective labour agreement. A company that has not written group HR reporting into these documents will struggle to rely on the exemption. The law has one more exemption, but a narrow one: an organisation storing data of its own employees on a cloud computing service (Article 20(6)(b) of Law 91/2025/QH15). It covers storage only; sending or sharing that same data with a parent company abroad is still a transfer that requires a dossier.

Why is it hard for EOR to rely on the personnel-management exemption?

Under EOR, the foreign client is not the employer: it signs no employment contract, issues no work rules, and is not in the same group as the provider. The data moves from the employer to a separate legal entity abroad — exactly the "transfer to an organisation abroad" case that the personnel-management exemption was not written for. No guidance yet addresses this point, so the prudent course is to treat it as an ordinary cross-border transfer and file the dossier.

An exemption from the dossier is not an exemption from the law. Every other duty still applies: a lawful basis for processing, security, a contract binding the recipient, and deletion of employee data when the employment contract ends, unless otherwise agreed or required by law (Article 25(2) of Law 91/2025/QH15). Separately, the impact assessment for processing personal data is a dossier of its own, which the controller must file within 60 days of the first processing (Article 21 of Law 91/2025/QH15) — an exemption from the transfer dossier does not exempt you from this one.

What must the contract with a foreign client bind the recipient to?

The contract must bind the recipient abroad to specific responsibilities, because a copy of that contract is a mandatory part of the impact assessment dossier (Article 18(2)(b) of Decree 356/2025/ND-CP). The principle to use is that the client may only view data to direct the work, and every other form of processing is excluded:

This list mirrors the activities that Article 2(6) of Law 91/2025/QH15 defines as "processing of personal data": collecting, analysing, aggregating, editing, providing, transferring. Excluding each of them from the client's scope is how a "view-only, no processing" clause gets a legal footing, rather than being a promise. When vetting a provider, ask whether this clause is ready — the full question list is in how to choose an Employer of Record in Vietnam.

Which employee data counts as sensitive under Decree 356?

Under Article 4 of Decree 356/2025/ND-CP, the four kinds of HR data most often classed as sensitive are ID card images, location determined through positioning services, biometric data and health status. By contrast, the ID number and phone number are basic data (Article 3).

That line decides what should go abroad:

The general rule: send aggregated or de-identified reports wherever possible. De-identified data is data that cannot help identify a specific person (Article 2(11) of Law 91/2025/QH15). Watch out for small groups: a "by department" payroll summary for a one-person department is still that person's data.

What are the risks of non-compliance?

The maximum fine for an organisation that breaches the cross-border transfer rules is 5% of its revenue in the preceding year; if there was no revenue in the preceding year, or 5% comes to less than VND 3 billion, the maximum is VND 3 billion (Article 8(4) and (5) of Law 91/2025/QH15).

Beyond the fine, three procedural milestones matter:

The six-month update matters especially for EOR: every new foreign client is a new recipient of data. When choosing a provider, you are entitled to ask directly whether its impact assessment dossier has been filed, and whether the data flow to your company has been added to it.

How does Nhan Kiet handle data for foreign clients?

Nhan Kiet separates roles by model. Under EOR, Nhan Kiet is the employer and the transferring party, so the impact assessment obligation rests with Nhan Kiet and is not passed to the client; the foreign client signs recipient commitments on a view-only, no-processing basis. Under PEO and payroll outsourcing, Nhan Kiet is a processor under contract and delivers reports to the client's Vietnamese entity.

This split tells each client exactly what its part is. With EOR services in Vietnam, you sign the recipient commitments. With payroll outsourcing or PEO, onward sharing with your group sits in your own company's labour regulations and dossier.

Nhan Kiet Manpower Supply Company Limited (tax code 0308022768) was founded in April 2009 and is now in its 17th year. It operates under labour sub-leasing Licence No. 15/2019/SHCM, holds ISO 9001:2015, ISO 45001 and ISO 14001 certification, and serves more than 500 clients with more than 40,000 workers across 34 provinces and cities.

Sources

This article summarises the rules for orientation; specific situations need individual advice.

Contact us

Companies that need to organise how employee data flows abroad under EOR, PEO or outsourced payroll can contact:

Need advice for your own headcount?
Call +84 908 636 108 or see labour compliance, payroll outsourcing, EOR Vietnam.

← All articles

Call +84 908 636 108 Message on Zalo