Data transfer for software development is an indispensable step in technology operations, yet it entails significant legal risks. Lack of control, breaches of processing purposes, or inadequate security measures may expose enterprises to severe sanctions.
I. Current situation relating to data transfer for software development
In the course of software development, many enterprises still transfer data without sufficiently robust control procedures, particularly when engaging third-party vendors or overseas partners.

Failure to adequately assess legal, security, and compliance risks relating to data protection increases the likelihood of data leakage, misuse, and the emergence of legal liabilities.
II. Concept of data transfer for software development
To properly understand the associated risks and legal obligations, enterprises must grasp the true nature of data transfer for software development, including the scope of shared data, the purposes of use, and the responsibilities of the participating parties.
1. What is data transfer for software development?
Data transfer for software development refers to an enterprise providing, sharing, or allowing another party to access data (including personal data, internal data, and business data) for the purposes of software design, programming, testing, operation, or upgrading in accordance with the agreed objectives.
2. What risks may arise when enterprises transfer data for software development?
When transferring data for software development, enterprises may face various legal and operational risks. In particular, data may be subject to leakage, theft, or unauthorized access during transmission, storage, or processing.
The data recipient may use the data for improper purposes, beyond the agreed scope of software development, or continue to retain or disclose the data to third parties without authorization.
These risks not only result in violations of data protection regulations, the emergence of compensation liabilities, and administrative sanctions, but also seriously affect enterprises’ reputation, trade secrets, and operational stability.
III. Legal provisions relating to data transfer for software development
Data transfer activities serving software development must comply with legal regulations on personal data protection, cybersecurity and information security, and confidentiality obligations in civil transactions, in order to ensure that data is used for the proper purposes and within the permitted scope, while minimizing legal risks for enterprises.
1. What principles must enterprises comply with when transferring data for software development?
When transferring personal data for software development, enterprises must fully comply with the following principles:
(i) Principles under the Law on Personal Data Protection 2025 (Article 3)
- Compliance with the Constitution, this Law, and other relevant legal provisions.
- Collection and processing of personal data strictly within lawful, specific, and clearly defined purposes and scopes.
- Ensuring the accuracy of personal data, with timely rectification, updating, and supplementation where necessary; retention only for a period consistent with the processing purposes, unless otherwise provided by law.
- Implementation of appropriate institutional, technical, and human measures in a coordinated and effective manner to protect personal data.
- Proactive prevention, detection, deterrence, and timely handling of violations of personal data protection laws.
- Protection of personal data in conjunction with safeguarding national interests, socio-economic development, national defense, security, and foreign relations, while ensuring a balance between personal data protection and the lawful rights and interests of agencies, organizations, and individuals.
(ii) Principles under the Data Law 2024 (Article 5)
- Compliance with the Constitution, this Law, and other relevant legal provisions; ensuring human rights, citizens’ rights, and other lawful rights and interests of agencies, organizations, and individuals.
- Ensuring openness, transparency, and equality in access to, exploitation, and use of data in accordance with law.
- Accurate collection, updating, and adjustment of data with continuity; ensuring integrity, reliability, security, and safety.
- Data protection to be implemented in a coordinated and rigorous manner alongside data development and deployment.
- Storage, connectivity, coordination, sharing, exploitation, and use of data to be conducted in an efficient, simple, and convenient manner for agencies, organizations, and individuals in public service provision, administrative procedures, and other activities.
In addition, data transfer for software development must comply with internal procedures and data governance standards promulgated by enterprises, in order to ensure control, security, and accountability throughout the entire process.
2. What conditions must third parties participating in data transfer for software development satisfy?
Pursuant to Clause 10, Article 2 of the Law on Personal Data Protection 2025, a third party refers to an organization or individual that is neither the data subject nor the data controller or data processor, but participates in personal data processing in accordance with law. In the context of data transfer for software development, third parties must satisfy the following legal and practical conditions:
First, participation in data processing within a lawful scope. Although the Law on Personal Data Protection 2025 does not separately stipulate specific rights of third parties, it follows from the legal definition that third parties may only participate in personal data processing activities (such as collection, analysis, encryption, anonymization, transfer, storage, or deletion) where such activities are consistent with the established purposes, scope, and legal basis agreed among the relevant parties.
Second, compliance with data subject consent requirements, except where otherwise permitted by law. Third parties may process personal data only where valid consent has been obtained from data subjects, except in cases where consent is not required, including:
- Protection of life, health, honor, dignity, or lawful rights and interests of the data subject or others in emergency situations;
- Prevention and response to emergencies threatening national security, terrorism, crime, or legal violations;
- Performance of state management or execution of public duties by competent authorities;
- Performance of agreements entered into by the data subject with relevant agencies, organizations, or individuals;
- Other cases as prescribed by law.
Third, compliance with confidentiality and legal liability requirements. Third parties must comply with personal data protection obligations, implement appropriate technical and organizational measures, and bear legal liability where data processing causes damage or violates data protection regulations.

In summary, third parties may only participate in data transfer for software development where there is a clear legal basis, compliance with processing purposes, assurance of data security, and adherence to the legally permitted scope.
3. Are there any regulations on the retention of data transferred for software development?
At present, there are no specific and standalone legal provisions directly governing the retention of data transferred solely for software development purposes. However, retention obligations in such cases are indirectly regulated by general legal provisions on data and personal data protection.
Pursuant to Article 14 of the Data Law 2024 (as guided by Article 5 of Decree No. 165/2025/ND-CP), for organizations and individuals that are not state authorities, data owners have the right to decide on the retention of data collected, created, or owned by them. Where data transferred for software development constitutes important data or core data, retention must comply with specific security and safety requirements under the Data Law; the storage location and infrastructure may be agreed by the parties, including storage at the national data center under a service contract.
Concurrently, under Article 18 of the Law on Personal Data Protection 2025, data controllers, data processors, and third parties are permitted to retain personal data in forms suitable to their operations, but must apply data protection measures throughout the retention period. The storage, access, exploitation, or interconnection of data must be consistent with processing purposes, compliant with law, and in accordance with the parties’ agreements.
4. What sanctions apply where data transfer for software development is conducted for improper purposes?
Where data transfer for software development is conducted for purposes inconsistent with those notified or agreed, or in violation of personal data protection regulations, the relevant organizations and individuals are subject to sanctions under Article 8 of the Law on Personal Data Protection 2025, including:
- First, administrative sanctions depending on the nature and severity of the violation. In particular, unlawful trading in personal data may be subject to fines of up to ten times the amount of illicit gains; violations relating to cross-border transfer of personal data may be subject to fines of up to 5% of the previous year’s revenue.
- For other violations in the sector of personal data protection, the maximum administrative fine may reach 3 billion VND for organizations; individuals committing the same acts are subject to fines at half of the organizational level.
In addition, where improper-purpose data transfer causes serious consequences and infringes upon the lawful rights and interests of individuals, organizations, or society, criminal liability may arise under relevant criminal law provisions.
Where unlawful transfer, disclosure, or use of financial data causes serious consequences, criminal liability may be imposed. Under Article 288 of the Penal Code 2015 (as amended in 2017) on the offense of illegally providing or using information on computer networks or telecommunications networks, unlawful use of others’ information on such networks, including personal financial data, that infringes upon lawful rights and interests may result in fines or imprisonment depending on the severity of the violation.
In addition, where actual damage is caused, the breaching party must compensate for civil damages according to Article 584 of the Civil Code 2015 , including property damage, loss of income, remediation costs, and moral damages (where legally justified).
IV. Questions regarding data transfer for software development
In practice, enterprises often raise concerns regarding legal conditions, responsibilities of the parties, and risk control measures in the course of data transfer for software development. The following addresses commonly raised questions to facilitate proper understanding and compliance.
1. Is a separate internal control procedure required for data transfer for software development between internal departments?
Pursuant to Clause 4, Article 7 of Decree No. 356/2025/ND-CP, where agencies or organizations share personal data among internal departments for the established processing purposes, they must establish internal control procedures governing data sharing and use. Such procedures ensure that data is used within the proper scope, authority, and purpose.
Enterprises must also implement measures to prevent internal risks, particularly to prevent personnel from unauthorized disclosure of personal data to third parties. It demonstrates that even internal data transfers for software development must not be conducted arbitrarily, but must be subject to clear, transparent, and accountable control mechanisms.
2. How long must enterprises retain records relating to data transfer for software development?
Pursuant to Clause 1, Article 27 of Decree No. 53/2022/ND-CP, data retention periods are calculated from the time the enterprise receives a retention request until the request ends, with a minimum retention period of 24 months. Such a requirement applies to data subject to mandatory retention under Article 26 of Decree No. 53/2022/ND-CP, including data serving cybersecurity assurance and related activities.
In addition, system logs used for investigating and handling cybersecurity violations must be retained for at least 12 months. With respect to data transfer for software development, enterprises should assess the nature of the data and the applicability of the Law on Cybersecurity and Decree No. 53/2022/ND-CP to determine corresponding retention obligations, and establish appropriate internal retention procedures to ensure compliance and readiness for inspection or audit when required.
3. What liabilities arise if data leakage occurs during data transfer for software development?
Depending on the nature, severity, and consequences of the violation, enterprises may be subject to the following sanctions under Article 8 of the Law on Personal Data Protection 2025:
- Administrative sanctions:
- Where data leakage does not involve unlawful trading in data and does not constitute cross-border transfer, the maximum fine under Clause 5, Article 8 is up to 3 billion VND for organizations.
- Where violations involve cross-border transfer of personal data, the maximum fine under Clause 4, Article 8 is up to 5% of the enterprise’s revenue in the immediately preceding year.
- Where unlawful trading in personal data occurs, the maximum fine under Clause 3, Article 8 is up to ten times the illicit gains.
- Criminal liability: Where data leakage satisfies the constituent elements of criminal offenses under the Penal Code 2015 (as amended in 2017), particularly Article 289 on illegal intrusion into computer networks, telecommunications networks, or electronic means of others, the relevant organizations or individuals may be subject to criminal liability in accordance with law.
- Civil liability for damages: Where data leakage causes actual damage to data subjects or third parties, enterprises must compensate for damages pursuant to Article 584 of the Civil Code 2015, irrespective of whether administrative sanctions have been imposed.
Data leakage in the course of data transfer may therefore expose enterprises to substantial fines (up to 3 billion VND, 5% of revenue, or ten times illicit gains), in addition to potential criminal liability and civil compensation obligations, depending on the specific circumstances.
4. Is it necessary to prepare minutes or documentation evidencing the data transfer process for software development?
Enterprises are required to prepare and retain records and documentation evidencing the data transfer process where personal data is processed in the course of software development.

Specifically, pursuant to Article 21 of the Law on Personal Data Protection 2025 (as guided by Article 19 of Decree No. 356/2025/ND-CP):
- Data controllers or entities that both control and process data must prepare and retain personal data processing impact assessment dossiers and submit one original copy to the specialized authority for personal data protection within 60 days from the commencement of data processing.
- Data processors (e.g., outsourced software development providers) must also prepare and retain impact assessment dossiers in accordance with their agreement with the data controller.
- Such dossiers are prepared once for the entire operational period, but must be updated where there are changes in purposes, scope, data categories, security measures, or transfer modalities.
- Where dossiers are incomplete or non-compliant, the competent authority may require supplementation.
In practice, records should include data transfer minutes, data processing agreements, personal data processing impact assessments, internal security procedures, and access logs. These not only constitute legal compliance obligations, but also serve as evidence of compliance responsibilities in the cases of risks or disputes.
5. Are there legal restrictions when transferring data for software development to international software vendors?
Where Vietnamese enterprises engage international software development vendors, the transfer of data, particularly personal data collected in Vietnam, is subject to strict regulation under personal data protection laws and must not be conducted arbitrarily.
Pursuant to Article 20 of the Law on Personal Data Protection 2025, engagement of foreign software development partners typically constitutes cross-border transfer of personal data, including:
- Transfer of personal data stored in Vietnam to systems located outside Vietnam;
- Transfer of personal data by Vietnamese enterprises to foreign organizations or individuals; or
- Use of platforms located outside Vietnam to process personal data collected in Vietnam.
In such cases, enterprises are required to prepare cross-border personal data transfer impact assessment dossiers and submit one original copy to the specialized personal data protection authority within 60 days from the first transfer, unless exemptions apply. The assessment is conducted once for the entire operation but must be updated in accordance with law where changes occur.
The specialized authority for personal data protection is empowered to inspect cross-border data transfer activities and to require suspension of transfers where personal data is used for activities that may harm national defense, national security, or violate personal data protection regulations.
The law also provides for certain exemptions from impact assessment obligations, such as transfers by competent state authorities, enterprises storing employees’ personal data on cloud services, data subjects transferring their own personal data abroad, or other cases prescribed by the Government.
V. Why seek legal advice from NPLaw when issues arise in data transfer for software development
Data transfer in software development entails significant legal risks and is subject to multiple specialized regulatory regimes. NPLAW assists enterprises in assessing risks, advising on compliance obligations, reviewing contracts, and establishing lawful data transfer procedures, including in cross-border data transfer scenarios. Engagement of legal counsel helps enterprises minimize violations, avoid sanctions, and ensure safe and effective project implementation.
The above information is for reference purposes only. For tailored advice on specific cases, please contact NPLAW for prompt consultation.