According to new legal framework, a Vietnamese bank cannot treat data privacy as 1 clause in a cloud contract. The question is who controls customer data at each step of customer journey, including when a cloud provider stores or processes it.
Law on Personal Data Protection, Law 91/2025/QH15
Decree 13/2023/ND-CP was the personal-data instrument took effect in 2023, but in 2026 it is no longer enough to describe the current framework by itself. In Jan 2026, Vietnam has the Law on Personal Data Protection, Law 91/2025/QH15, effective from January 1, 2026. Decree 356/2025/ND-CP provides detailed implementation rules. A bank should confirm the current consolidated obligations and transitional position with qualified Vietnamese counsel. Pls note that this article is an engineering interpretation, not legal advice
What the legal layer digital bank need to manage
The national personal-data regime governs how personal data is protected and processed. For a digital bank, this means a cloud decision is also a data-processing decision. The bank needs a legally reviewed basis for what data is handled, for which purpose, by which parties, for how long, and under what conditions it may be disclosed or transferred.
Banking rules add system-security duties. Article 25 of Circular 09/2020/TT-NHNN was repealed by Circular 50/2024/TT-NHNN, so the current text and amendments must be checked before relying on a specific clause. The provisions that remain applicable set minimum information-system security requirements for covered banking organizations.
For cloud services, the Circular includes minimum criteria for selecting a third party, contract terms concerning security and oversight, and monitoring of the service. It also requires periodic compliance assessment for relevant third parties, including providers used by systems that process customer information or use cloud services. These are regulatory requirements, not optional architecture patterns.
The legal conclusion should come from counsel and the institution's compliance function. Bank should not infer that a cloud certification, a standard vendor contract, or encryption alone proves compliance.
How is this impact my engineering work
The first engineering artifact should be a data map. It should show which customer data enters each journey, where it is stored, which systems and parties process it, where copies and backups exist, and when each copy is deleted. Without that map, a privacy review will not efficient.
Next, attach controls to the map:
- Collect only the fields approved for the stated purpose;
- Define retention and deletion behavior for primary data, logs, backups, and exports;
- Restrict access by role and record sensitive access;
- Protect data in transit and at rest, with clear ownership of keys and secrets;
- Separate the bank's data from other cloud customers;
- Define how incidents, customer requests, investigations, and regulatory requests are handled;
- Test exit procedures so the bank can retrieve data and verify deletion when a service ends.
The implementation depends on the data, service, legal role of each party, and current regulatory text.
Accountability of the bank when using cloud provider services
A cloud provider can operate controls, produce audit evidence, and support incident response. It does not take over the bank's accountability for deciding why customer data is processed or whether the arrangement is acceptable.
In conclusion: work with legal, privacy team to review privacy and cloud security together, but keep their questions distinct. Privacy focus on whether the processing is lawful, limited, and accountable. Security focus how confidentiality, integrity, availability, and access are protected. A digital banking design needs both answers, supported by evidence that remains valid after the contract is signed.