Cross-Border Personal Data Transfer Impact Assessment (CTIA): Detailed Guidance for Businesses
What is CTIA? CBI provides an overview of the latest regulations on the legal basis, requirements, and procedures for preparing a Cross-Border Personal Data Transfer Impact Assessment (CTIA) dossier, helping businesses proactively comply with applicable regulations and manage risks associated with cross-border data transfers.

Illustrative image
1. Legal Basis and Concept of CTIA
A Cross-Border Personal Data Transfer Impact Assessment (CTIA) is an impact assessment dossier that must be prepared by agencies, organizations, and individuals when carrying out activities involving the transfer of personal data outside the territory of Vietnam.
Such activities are strictly regulated under:
- Law on Personal Data Protection (Law No. 91/2025/QH15);
- Decree No. 356/2025/ND-CP, which provides detailed regulations on the dossier requirements, conditions, and reporting obligations applicable to cross-border personal data transfers.
2. When Is Your Business Required to Prepare a CTIA Dossier?
Many businesses still assume that the obligation to prepare a Cross-Border Personal Data Transfer Impact Assessment (CTIA) dossier only arises when they directly “sell data to a foreign company.” However, pursuant to Clause 1, Article 20 of the 2025 Law on Personal Data Protection, and based on practical legal advisory experience, the CTIA obligation may arise as soon as a business transfers personal data outside Vietnam, transfers personal data to an overseas organization or individual, or allows an overseas organization or individual to access personal data stored in Vietnam.
Common scenarios that may constitute a cross-border transfer of personal data include:
- Transferring personal data stored in Vietnam to a data storage system located outside the territory of the Socialist Republic of Vietnam;
- An agency, organization, or individual in Vietnam transferring personal data to an organization or individual overseas;
- An agency, organization, or individual in Vietnam or overseas using a platform located outside the territory of the Socialist Republic of Vietnam to process personal data collected in Vietnam.
3. Core Components of a Legally Compliant CTIA Dossier
Pursuant to Article 18 of Decree No. 356/2025/ND-CP, a complete Cross-Border Personal Data Transfer Impact Assessment dossier includes the following key components:
| Dossier Component | Key Information to Be Included |
|---|---|
| CTIA Report in the prescribed form | Description of the type, purpose, and scope of the data transfer; data processing flows; storage infrastructure and systems of the recipient; information on relevant parties; legal basis for processing and consent of data subjects; data protection measures; assessment of the level of protection and associated risks; and risk mitigation measures. |
| Personal Data Transfer Agreement / Contract | Regulations governing the relationship and responsibilities between the transferring and receiving parties; purpose, scope, and types of transferred data; data processing and retention periods; deletion/destruction requirements; legal basis; and mechanisms for coordinating the handling of violations. |
| Relevant policies, procedures, regulations, and forms | Internal policies, procedures, regulations, forms, and other documents applied to the management and protection of personal data (including consent forms, etc.) and the implementation of cross-border personal data transfers. |
| Documents evidencing the data transfer activities | Records, documents, and supporting evidence demonstrating the scope, purpose, method, and actual implementation of the cross-border personal data transfer activities. |
4. Four-Step CTIA Implementation Process Supported by Legal Counsel
Our legal team assists businesses in streamlining their CTIA compliance process through the following four structured steps:
- Review and Identification of Cross-Border Data Flows:
Review the IT infrastructure to accurately identify data points that are transferred to or accessed from overseas. - Assessment of the Legal and Data Protection Safeguards of the Recipient:
Assess the recipient’s security mechanisms and actual capacity to protect personal data, as well as the risks associated with the cross-border transfer. - Drafting and Standardization of Data Transfer Agreements:
Develop the required data protection provisions in accordance with the Law on Personal Data Protection and Decree No. 356/2025/ND-CP. - Completion and Submission of the Dossier:
Submit one original complete dossier to the Cybersecurity and High-Tech Crime Prevention Department (A05) of the Ministry of Public Security within 60 days from the date on which the cross-border personal data transfer is initiated, and provide explanations or supporting information when requested by the competent authority.
Our Cross-Border CTIA Consulting and Dossier Preparation Services
Cross-border personal data transfers involve potential legal risks and require businesses to strictly comply with regulations on personal data protection and cybersecurity. With a team of lawyers possessing in-depth experience in this field, CBI works alongside businesses to assess potential risks, develop appropriate data transfer arrangements, and prepare and finalize CTIA dossiers, thereby supporting legal compliance, data security, and operational efficiency.
This article is provided for general informational purposes only and does not constitute legal advice for any specific case. The legal provisions referred to in this article are effective as of the date of publication but may have been amended, supplemented, replaced, or expired by the time the reader accesses this article. Readers are therefore recommended to seek advice from a lawyer before applying the information herein.
For any inquiries or requests for consultation regarding personal data impact assessment procedures and other related legal services, please contact CBI Law Company Limited for further assistance.