You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 25, 2021

Vietnam Issues New Draft Decree on Personal Data Protection

On February 9, 2021, Vietnam’s Ministry of Public Security (MPS) finally released the full text of the Draft Decree on Personal Data Protection (the “Draft”) for public consultation, after having released an outline in December 2019, with an ambitious goal for the Draft to be promulgated and take effect on December 1, 2021.

The Draft is divided into six chapters and 30 articles, providing comprehensive coverage of personal data protection and some brand-new requirements. Notable contents of the Draft include the following:

  1. Re-categorization of personal data into basic personal data and sensitive personal data;
  2. New data processing requirements, including new legal bases for data processing and disclosure without consent; specification of the forms of consent; regulations for data processing for research and statistical purposes and automated data processing; and time limits for data retention;
  3. New data protection measures, including de-identification/encryption requirements, appointment of data protection officers, data accessibility from government authorities, and registration for processing of sensitive data and cross-border transfer of data;
  4. Establishment of a new Personal Data Protection Commission (PDPC) under the MPS; and
  5. New administrative sanctions for violations, including fines of up to 5% of the revenues earned from violating activities.

Among the various newly introduced requirements proposed in the Draft, Article 20 (Registration of Processing of Sensitive Personal Data) and Article 21 (Cross-Border Transfer of Personal Data) are notably problematic, and seem infeasible for the operation of various businesses and industries.

Article 20 – Registration of Processing of Sensitive Personal Data 

The Draft’s Article 20 requires that sensitive personal data be registered with the PDPC prior to processing. The scope of sensitive personal data as defined in the Draft ranges from specific types of data such as gender, biometrics, criminal records, and location to very broad concepts such as political and religious views and social relationships.

Among the required contents of the registration application for processing of personal data is an impact assessment report that clearly points out the potential harm to data subjects due to such proposed processing and measures to manage, minimize, or eliminate such harm. The PDPC will process the applications within 20 working days from the date of receipt of a valid application, which means the date that all information and documents provided in the application are acceptable to the officers in charge.

Although the government’s intent is to protect persons and entities covered by the Draft from any improper and harmful processing of their personal data—a laudable goal—this registration requirement potentially creates a huge impact on businesses in terms of time, costs, and administrative procedures. In reality, almost every company, whether local or overseas entity, needs to process its employees’ sensitive data (such as health data, criminal records, etc.) for various legitimate purposes. To be eligible to do so under the Draft, companies will have to prepare and submit applications to the PDPC for approval. Not only will this impose significant costs on companies in terms of time, money, and human resources, but it is highly doubtful that the PDPC would have sufficient resources to process the expected volume of applications within the specified timeline.

Article 21 – Cross-Border Transfer of Personal Data

Similarly, Article 21 of the Draft requires that, before transferring Vietnamese citizens’ personal data out of Vietnam, the following four conditions be fulfilled: (i) consent must be obtained from the data subjects; (ii) the original data must be stored in Vietnam; (iii) the data transferor must have proof that the recipient country has personal data protection at a level equal to or higher than the level specified in the Draft; and (iv) a written approval for transfer must be obtained from the PDPC.

The Draft provides an exemption to the foregoing requirement, when there is (a) consent from the data subject, (b) approval from the PDPC, (c) a commitment from the data processor to protect the data, and (d) a commitment from the data processor to apply measures to protect the data. (It is unclear from the wording of the Draft whether the data transferor needs to meet one or all of these criteria to be eligible for the exemption, but presumably all four must be met.)

In order to obtain a written approval from the PDPC, an application must again include an impact assessment report with an assessment of potential harm and measures to manage, minimize or eliminate such harm. The PDPC has 20 working days from the date of submission to process applications for approval.

It is apparent that these requirements in Article 21 could create a barrier to trade and the flow of data, and increase cost, time, and human resources requirements for companies across many industries. For example, there are a significant number of multinational companies operating in Vietnam that need to regularly process personal data, and they usually process such data in a selected country outside of Vietnam or use cloud services with physical servers located outside of Vietnam. This practice is very common for many industries, including e-commerce, banking, travel, education, health care, etc. If all companies sending personal data overseas have to store data in Vietnam, it would create huge costs and additional work and overhead for them. Moreover, the process for applying for approval from the PDPC would unavoidably delay transactions and data transfers, which usually need to be processed instantly.

The Draft is open for public consultation from February 9 to April 9, 2021, and merits the urgent attention of industries, associations, and businesses to share comments with the MPS in order to develop legislation which is effective as well as feasible for implementation, balancing data subjects’ rights with the smooth operation of business.

As the effective date for this legislation could come later this year, it is also important for companies to get a head start on evaluating data transfers and processing within their own organization, and start formulating plans.

For further information about the Draft, please contact us at [email protected].

RELATED INSIGHTS​ 

September 30, 2026
On September 15, 2026, Vietnam’s Ministry of Finance (MOF) released for public consultation a draft circular on reporting and information disclosure in the pilot crypto asset market. The draft implements Resolution No. 05/2025/NQ-CP on the Pilot Implementation of the Crypto Asset Market in Vietnam and provides further detail on how licensed crypto asset service providers (“CASPs”) will be supervised once the market becomes operational. The draft indicates a data-intensive supervisory model, with licensed CASPs serving as the first line of market oversight. Public Disclosure Requirements The draft imposes detailed public disclosure requirements on CASPs, aimed primarily at market transparency. CASPs and crypto asset issuers must make disclosures in both Vietnamese and English, retain reported and disclosed information for at least 10 years, and keep information published on their websites accessible for at least five years. For CASPs, disclosure obligations arise both periodically and when specific events occur. A CASP must announce any crypto asset to be admitted to trading on its website at least seven days before trading begins and publish periodic financial statements. Certain extraordinary events and information requested by the MOF must generally be disclosed within 24 hours. CASPs must also provide ongoing market information. During trading hours, they must publish key trading data, including prices and volumes, daily highs and lows, average prices, the three best bid and offer levels, and transactions by foreign investors. By 9:00 a.m. each trading day, they must publish specified information on the previous day’s trading activity. Regulatory Reporting Requirements Separate from public disclosure, the draft requires CASPs to provide regulators with detailed information enabling ongoing supervision of their operations and the market. For market activity, CASPs must report decisions to admit or remove a crypto asset from trading within 24 hours, submit previous-day trading data to the State Securities Commission
September 24, 2026
Vietnam is implementing and developing a broad package of regulatory reforms that could reshape how IP, data, digital platforms, and product authenticity are regulated and enforced. Several of the key measures have been led by the Ministry of Public Security in its legislative and administrative capacity, as part of a broader government effort. The core reform package consists of four key legal instruments: proposed amendments to the Criminal Code, a proposed new Data Security Law, a draft Decree on Product Identification, Authentication and Traceability, and the newly enacted Decree No. 330/2026/ND-CP. These instruments include rules on criminal enforcement, data security, electronic identification, product identification and traceability, administrative violations, and cybersecurity sanctions. Combined, these measures will affect copyright enforcement, industrial property rights, trade secrets, AI training data, product provenance, online takedowns, valuation of counterfeit goods and electronic evidence. It is worth noting that, in addition to strengthening criminal penalties for IP crimes, Vietnam’s emerging regulatory framework increasingly treats infringement, data misuse, product authentication, and platform-enabled violations as interconnected regulatory and enforcement challenges. For rights holders and foreign investors, this could mean stronger tools against counterfeiting and online infringement, but also more compliance obligations around data, traceability, AI, platform controls and government-facing reporting. Expansion of Criminal IP Enforcement Proposed amendments to Article 225 of the Criminal Code would expand criminal copyright exposure beyond reproduction and distribution to cover large-scale commercial public performance and online communication of works, phonograms and video recordings. This is important because piracy is increasingly about streaming, unauthorized communication, and platform access models rather than physical copying. Aggravated copyright infringement could be subject to up to 10 years in prison for individuals and fines of up to VND 6 billion (about USD 228,300) for commercial legal entities. The amended Article 226 would expand criminal industrial property liability beyond
September 17, 2026
Thailand’s Office of the Consumer Protection Board (OCPB) has released for public comment a draft bill to amend the Consumer Protection Act B.E. 2522 (1979), the country’s foundational consumer protection legislation. The draft amendment aims to modernize the nearly five-decade-old framework to address the rapid growth of digital commerce, online advertising, influencer marketing, and new business models. The public consultation period is open until October 10, 2026. Expanded Definitions Covering Digital Commerce The draft significantly broadens several core definitions to capture modern commercial activities: “Consumer” is expanded to include natural persons and nonprofit juristic persons who purchase or receive services, including those solicited by businesses and end users who do not directly pay for the goods or services. “Business operator” now explicitly covers advertising business operators and hired advertising persons, such as influencers and content creators. “Advertising media” is expanded to include digital platforms, social media, and social media user accounts. “Label” now encompasses electronic labels—symbols, codes, or other electronic formats displaying product information. Influencer and Advertising Disclosure Requirements In addition to these expanded definitions, “hired advertising person for selling goods or services” is a new definition covering influencers, content creators, live streamers, affiliate marketers, and virtual online media operators who receive monetary compensation or other benefits for advertising goods or services. Hired advertising persons—including influencers and content creators—must disclose to consumers that content is advertising and reveal their relationship with the business owner. Disclosure is required when the business owner employs the advertiser, pays or provides other benefits for the advertisement, or provides free or discounted products or services. These requirements apply where consumers would not otherwise know that the business has a connection to the person presenting the content. Labeling Requirements for Importers The draft introduces a clearer labeling obligation for importers of label-controlled goods, who must
September 11, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published a new five-year master plan that will bring significant regulatory changes to the broadcasting and digital media sectors, including formal licensing requirements for internet-based audiovisual services. The Master Plan for Broadcasting and Television, 3rd Edition (B.E. 2569–2573/2026–2030) was published in the Government Gazette on September 1, 2026, and will affect OTT platforms, internet-based audiovisual service providers, and traditional broadcasters. Licensing Reform The NBTC will develop new licensing frameworks ahead of existing digital television license expirations, which are slated to occur between 2028 and 2030. This creates both uncertainty and opportunity for incumbents and new market entrants. New licensing criteria will also be developed for audiovisual services delivered over the internet, meaning previously unregulated internet-based providers may face licensing, fee, and content obligations for the first time. The plan also calls for a new law to govern converged communications services. OTT Regulation and Content Oversight The plan explicitly acknowledges and aims to lessen the regulatory asymmetry between traditional broadcasters—which are subject to licensing, fees, and content regulation—and internet-based services that currently face fewer obligations. The NBTC intends to develop regulatory frameworks to bring internet-based audiovisual services, including OTT platforms, streaming services, and user-generated content platforms, under content, consumer protection, and licensing requirements. Consumer Protection and Digital Rights The NBTC will strengthen its oversight of broadcasting, television, and telecommunications operators to ensure compliance with consumer protection and personal data protection requirements. This includes updating relevant notifications and orders and more strictly enforcing rules against practices that unfairly exploit consumers. These measures may layer NBTC-specific requirements on top of Thailand’s existing Personal Data Protection Act obligations. Stricter enforcement against practices that exploit consumers is a priority, with particular scrutiny on advertising practices. The NBTC will modernize complaint resolution processes, meaning service providers should