You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 18, 2023

Vietnam Issues Landmark Personal Data Protection Decree

On April 17, 2023, the Vietnamese government issued Decree No. 13/2023/ND on the Protection of Personal Data (“PDPD”), following extensive public consultations and multiple rounds of review since the first release of its draft version in February 2021. This is a long-awaited legal instrument which is designed to be the very first comprehensive regulation on the protection of personal data in Vietnam. The PDPD is set to take effect on July 1, 2023, without any transitional period. All Vietnamese and foreign organizations and individuals located in Vietnam and/or directly participating in or related to personal data processing activities in Vietnam must comply with the PDPD.

As expected, the PDPD sets out significantly new requirements on the processing of personal data. The most critical provisions include:

  • Eight principles for the processing of personal data: (i) lawfulness, (ii) transparency, (iii) purpose limitation, (iv) data minimization, (v) accuracy, (vi) integrity, confidentiality, and security, (iv) storage limitation, and (viii) accountability (Article 3).
  • Critical new definitions and concepts, notably including personal data (Article 2.1); basic personal data (Article 2.3); sensitive data (Article 2.4); data subject (Article 2.6); data controller (Article 2.9); data processor (Article 2.10); parties controlling and processing personal data (Article 2.11); third parties (Article 2.12); and cross-border transfer of personal data (Article 2.14).
  • Eleven data subject rights, including the right to know; right to consent; right to access; right to withdraw consent; right to delete data; right to restrict data processing; right to request the provision of data; right to object to data processing; right to complain, denounce and initiate lawsuits; right to claim compensation for damage; and right to self-defense (Article 9).
  • Specific responsibilities of data controllers (Article 38), data processors (Article 39) and third parties (Article 41).
  • Specific requirements in the exercise of data subject rights (Articles 14-16).
  • Rules on data subjects’ consent, including the requirements on validity, acceptable formats and withdrawal of consent (Articles 11 and 12).
  • Requirements on data processing impact assessment (Article 24).
  • Conditions for cross-border transfer of personal data, including a transfer impact assessment and post-transfer notification sent to the Department of Cyber Security and Hi-Tech Crime Prevention of the Ministry of Public Security (Article 25).
  • Rules on privacy notices, including timing to send the notices and mandatory content of the notices (Article 13).
  • Rules on processing of personal data obtained through audio and video recording activities in public places (Article 18).
  • Rules on processing of personal data of individuals who are declared missing or deceased (Article 19).
  • Processing of children’s personal data (Article 20).
  • Rules on protection of personal data in the business of marketing services and introducing advertising products (Article 21).
  • Cases where personal data can be processed without consent (Article 17).
  • Measures to protect personal data in general (Article 26), basic personal data (Article 27) and sensitive personal data (Article 28). The measures to protect sensitive personal data include assigning a data protection officer.

The PDPD will have far-reaching implications across virtually all business operations in Vietnam. We will provide further analysis on the anticipated impact of the PDPD in upcoming articles to help companies chart their compliance strategies.

Related: For a deeper exploration of the changes introduced by the PDPD, please see “A Closer Look at Vietnam’s First-Ever Personal Data Protection Decree.”

RELATED INSIGHTS​ 

November 12, 2025
Thailand’s Customs Department has announced the cancellation of the longstanding de minimis exemption, which waives import duties on goods valued at THB 1,500 or less, as of January 1, 2026. This policy shift will directly impact e-commerce, logistics, and retail sectors, and will have wide-ranging implications for any company involved in cross-border trade with Thailand. Background Under current regulations, imported goods with a customs value (cost, insurance, and freight, or “CIF”) of THB 1,500 or less are exempt from import duties. This has been a cornerstone of the cross-border e-commerce model, allowing for the duty-free import of millions of small parcels. Under the new policy effective January 1, 2026, all imported goods, regardless of value, will be subject to assessment for import duties upon entry into Thailand. The stated rationale for this change is to create fair competition for Thai small and medium-sized enterprises (SMEs), which must pay VAT and other costs on their goods, putting them at a price disadvantage against foreign sellers who utilize the de minimis loophole. Business Implications This policy change will create new costs, compliance burdens, and operational challenges. For foreign e-commerce sellers and platforms: The most direct impact will be the addition of import duties to low-value items. Assuming the costs are passed on to the consumer, the higher prices and potentially more complex or slower customs clearance processes could lead to increased cart abandonment and reduced consumer demand. Businesses should review their pricing models and develop a clear strategy for calculating, declaring, and paying these new duties. For logistics providers and customs brokers: The administrative burden will be considerable. Carriers that previously handled millions of nondutiable parcels will now be required to process them for duty assessment and collection. This may necessitate new IT systems and streamlined processes to avoid delays at
November 7, 2025
Thailand and the United States signed a memorandum of understanding (MOU) titled “Cooperation to Diversify Global Critical Minerals Supply Chains and Promote Investments” on October 26, 2025, signaling a new strategic alignment aimed at developing Thailand’s mineral sector, particularly in rare earth elements (REEs). The MOU has implications for investments in technology, manufacturing, and other related sectors. This update outlines the key provisions of the MOU and the potential opportunities and legal navigating points for businesses. Objectives The primary driver of this agreement is the US initiative to diversify global supply chains for critical minerals and reduce reliance on current market leaders, particularly China. For Thailand, it represents a major opportunity to attract high-tech investment and develop its downstream processing industries. The cooperation is set to focus on five main areas: Technical knowledge: Exchange of technical expertise and international best practices to strengthen Thailand’s mining and processing sector. Joint cooperation: Establishing workshops, seminars, and scientific collaboration to boost innovation. Regulatory practice: Promoting good governance and streamlining regulatory and licensing procedures. Information sharing: Sharing data on potential projects and global market prices. Full-value chain: The MOU covers the entire mineral lifecycle, from exploration and extraction to processing, refining, and recycling. “First Opportunity to Invest” Clause The most debated provision within the MOU states that “participants expect to have the first opportunity to invest . . . in critical minerals assets that may be sold in Thailand.” Business implications: This clause is widely interpreted as granting US companies a first look or preferential access to investment opportunities in Thailand’s critical minerals sector. This could be a significant advantage for US-based or affiliated companies in mining, technology, and energy seeking to secure a foothold in a developing REE supply chain. Thai government position: Thai officials, including the prime minister, have publicly clarified
October 31, 2025
On September 29, 2025, Thailand’s Office of the Personal Data Protection Committee (PDPC Office) published its Regulations on the Review and Certification of Binding Corporate Rules B.E. 2568 (2025) (the Regulations). The Regulations provide clarity on the PDPC Office’s approach to reviewing and certifying binding corporate rules (BCRs) under Section 29 of the Personal Data Protection Act B.E. 2562 (2019) (PDPA), and aim to facilitate international data transfers within a group of undertakings or enterprises (a “corporate group”). In conjunction with this development, the PDPC Office also approved BCRs for two companies operating in Thailand on September 30, 2025. This milestone represents the first concrete progress since the PDPC’s Notification on Criteria for the Protection of Personal Data Sent or Transferred to a Foreign Country pursuant to Section 29 of the PDPA B.E. 2566 (2023) came into effect in March 2024. Some key features of the Regulations are set out below. Categorization of BCRs BCRs are classified into two types: (1) BCRs for Controllers (BCR-C) and (2) BCRs for Processors (BCR-P). The category must be clearly specified when submitting the BCRs to the PDPC Office. Documentation Requirement The applicant must prepare and submit the application (a standard template may be provided by the PDPC Office in the future) along with supporting documents for review and certification in the Thai language. If the supporting documents are in a foreign language, a certified Thai translation should be provided. The translation must be notarized by a notary public or qualified person. Supporting documents may include, among others, a binding instrument such as an intra-group agreement, or a list of entities subject to the BCRs. Expedited Process Requirement Organizations with existing BCR approvals under the EU or UK GDPR, or from countries announced by the PDPC under Section 28, may apply through an
October 26, 2025
AI-generated songs are now making waves in Vietnam on platforms like TikTok, with tracks such as “Say mot doi vi em” quickly gaining popularity and sparking widespread attention. This phenomenon raises a host of legal and ethical questions: Who is the author of these songs? Can they be protected by copyright? Who is responsible if there is an infringement? These questions are becoming increasingly urgent as AI music becomes more mainstream in Vietnam. Copyright Protection for AI-Generated Music in Vietnam Under current Vietnamese law, copyright protection is reserved for works that bear the mark of human creativity. The 2022 amendments to Vietnam’s Intellectual Property Law reaffirm that only works created by humans are eligible for copyright. In practice, if a human meaningfully contributes to the creative process—by providing prompts, making selections, editing, or arranging—their contribution may be protected. However, if a song is generated entirely by AI without significant human input, it is unlikely to qualify for copyright protection. When an AI-generated song does not qualify for copyright protection, the question arises as to whether the person who writes the prompts, edits, or compiles the work can still be considered the owner of an asset under the Vietnamese Civil Code. According to Article 105 of the Civil Code 2015, assets include objects, money, valuable papers, and property rights. While AI-generated music that is not protected by copyright is not considered money or valuable papers, it may be regarded as an object (in the form of a digital file or recording) or as a property right if it can be possessed, used, transferred, or exploited for value. Use of AI-Generated Works Without Copyright Protection If a song is not protected by copyright, does that mean anyone can use it freely? Not necessarily. The absence of copyright does not mean the