You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2024

Vietnam Releases First Draft of New Personal Data Protection Law

On September 24, 2024, the government of Vietnam issued the first draft of a new Law on Personal Data Protection (“Draft PDPL”). As foreshadowed in our previous legal update, the Ministry of Public Security has been very active in developing this draft law. With this draft, they promise to continue their considerable efforts to establish a robust personal data protection culture in Vietnam, as the Draft PDPL indicates a tentative entry into force on January 1, 2026.

With a tentative adoption by the National Assembly in May 2025, the Draft PDPL does not include any transition period, save for micro-enterprises, SMEs, and startups, which are only exempted from appointing a data protection department in their first two years of existence, while the timeline to comply with other obligations under the PDPL remains the same as for other enterprises.

The Draft PDPL includes 68 articles, divided into seven chapters, making it more extensive than last year’s Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), and expressly addresses personal data protection in many fields, including marketing services, behavioral advertising, big-data processing, AI, cloud computing, labor monitoring and recruitment, financial and credit information, health and insurance, and others.

It remains unclear how the PDPL will interact with the PDPD (whether it will replace its predecessor or coexist with it), although the Draft PDPL provides that it will prevail over any laws that have provisions on personal data protection that differ from the provisions of the PDPL.

Among the important new developments of the Draft PDPL when compared to the PDPD, we note:

  • Consent remains the main legal basis for processing, with limited exceptions (still not including “legitimate interest”). However, consent for cross-border transfer is further regulated under the Draft PDPL, including for intra-group sharing.
  • Data processing impact assessment dossiers for controllers and processors (“DPIA”) and transfer impact assessment for transferors (“TIA”) are retained, but, for the latter, the cases of transfer of personal data abroad have been further defined. These DPIAs and TIAs will have to be updated and submitted again to the authorities every six months or immediately upon material change.
  • New definitions have been inserted, such as “developers”, “personal data protection organization”, “personal data protection expert”, “de-identification of personal data”, “use of personal data for marketing”, “use of personal data for behavioral advertising”, and “personal data protection credit rating”, and other definitions currently found in the PDPD have been modified (e.g., land use right-related information has been included as “sensitive information”).
  • A data protection department must be appointed for basic personal data processing (it is no longer limited to sensitive personal data processing) and the Draft PDPL includes a recognition that a data protection department can be an external service provider (i.e., a personal data protection organization). The Draft PDPL further regulates this new service.
  • Certification mechanisms are introduced as credit ratings for personal data protection (high credibility, trust, pass, failing).
  • The 72-hour timeline to address certain data subjects’ requests and to notify the authorities in case of violation of the personal data protection regulations remains unchanged.

We will publish a deeper dive into the Draft PDPL shortly to provide you with more information on this new draft and draw comparisons with the PDPD, which was just enacted last year. [EDIT: Please see “Vietnam’s Draft Personal Data Protection Law: An In-Depth Look.”] Businesses are strongly encouraged to continue monitoring the development of this new legislation for preparation and to provide comments during the public consultation phase, which is open until November 24, 2024.

RELATED INSIGHTS​ 

May 9, 2024
On April 29, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) issued the master plan for personal data protection, which outlines the PDPC’s strategies for developing and enhancing the data protection framework in Thailand from 2024 to 2027. A draft of this four-year plan had previously been released for a public hearing on November 27, 2023. Overview The master plan sets out the long-term direction for the protection of personal data in Thailand, analyzing the current landscape, challenges, and obstacles encountered since the full enactment of the Personal Data Protection Act B.E. 2562 (2019) (PDPA). It aims to align with Thailand’s National Security Policy and Plan for 2024–2027 and focuses on key sectors in its initial two years. These sectors are: Public security and key government services; Retail and e-commerce; Information and communication technology and telecommunications; Finance, investment, and insurance; Public health; Tourism; and Education. Objectives The master plan’s goals include increasing organizational compliance with the PDPA, reducing data breaches, updating the PDPA to reflect current circumstances, introducing various PDPC e-services, and enhancing Thailand’s global competitiveness in data privacy and personal data protection. It sets targets and indicators of the plan’s success, such as achieving a 100% PDPA compliance rate across all sectors in Thailand and raising Thailand’s digital competitiveness to at least 30th in the World Digital Competitiveness Rankings from the IMD World Competitiveness Center. Strategic Initiatives To achieve these objectives, the master plan introduces four strategic initiatives: Effective and balanced PDPA enforcement: Develop standards, principles, criteria, tools, indicators, and data privacy governance, including law enhancements. A recent example of this is the PDPC’s launch of the Personal Data Protection Surveillance Centre (PDPC Eagle Eye) to monitor data breaches. Knowledge and trust enhancement: Build human capacity and trust by enhancing knowledge through initiatives like the forthcoming
May 3, 2024
Vietnam’s Ministry of Public Security (MPS) recently published on its website a dossier of the Draft Law on Data (the “Draft Law”) for public feedback, initiating a consultation period from February 26 to March 26, 2024. The dossier comprises a Policy Impact Assessment Report and a Summary Report on the implementation of existing legal documents governing data. An outline of the Draft Law was later circulated to relevant organizations for their input and commentary. The MPS drafted this legislation with several objectives, including bolstering national data infrastructure, advancing digital government while streamlining administrative procedures, fostering growth in the digital economy and building a digital society, and establishing a National Data Center. Comprising 65 articles across 6 chapters, the Draft Law is slated for implementation on January 1, 2026. The Draft Law currently is very preliminary, resembling a framework document. It features numerous provisions akin to policy mandates, yet only presents introductory concepts without further elaboration. Scope of Application The Draft Law applies to agencies, organizations, and individuals involved in data activities in Vietnam. This scope of application appears excessively broad and ambiguous, without a clear definition of “data activities”, leaving uncertainty regarding the breadth of this term’s coverage. Key Policy Groups The Draft Law focuses on four key policy groups: 1. Regulations on development, processing, and management of data This policy group focuses on matters relating to the collection, digitalization, and creation of data; assurance of data quality; data classification; data storage; data combination, adjustment, and updating; data strategy; data management; data sharing; provision of data to state agencies; data analysis and synthesis; data verification and authentication; data disclosure; access and retrieval of data; data encryption and decryption; data copying, transmission, and transfer; data revocation, deletion, and destruction; application of science and technology in data processing; identification and management
April 30, 2024
On March 25, 2024, Thailand’s Securities and Exchange Commission (SEC) published an amendment to its Notification re: Public Digital Token Offering to strengthen governance for initial coin offerings (ICOs). The amendments took effect on April 16, 2024, and reflect the SEC’s commitment to creating a safer and more transparent ICO environment, enhancing investor protection, and building confidence in ICOs as a fundraising tool. The key changes are outlined below: New Checks and Balances Requirements The new regulations require digital token issuers to implement checks and balances to protect investor rights—including an annual audit requirement and measures to prevent and manage conflicts of interest. These measures must be clearly disclosed in the ICO filing documents. In addition, certain project-related decisions must be approved by the issuer’s board of directors, which is also responsible for the accountability of such decisions. Improved Rules Concerning Voting Rights The SEC has introduced rules concerning voting rights and procedures for digital token holders, particularly for token types that previously lacked regulatory clarity. These rules specify the procedures for soliciting votes, the rationale behind vote requests, and the criteria for determining voting outcomes. The new rules, however, do not apply to real estate-backed tokens or infrastructure-backed tokens. Enhanced Advertising Regulations The SEC has revised advertising guidelines to ensure that investors receive essential information. The updated rules now require all ICO advertising to be fair and informative and to avoid misleading content. Advertisements must include appropriate risk warnings and a credible source for any claims made. The notification also stresses that it is the responsibility of digital token issuers to strictly supervise and ensure that those who create advertisements with or for an issuer comply with all relevant advertising regulations, including the following: Warning of investment risk: Advertisements must include warnings about investment risks and contact information
April 5, 2024
On March 15, 2024, Thailand’s Board of Investment (BOI) updated its investment incentives for software development and data centers by issuing a regulation replacing the previous categories of software or platforms for digital services or content (category 8.1) and data centers (category 8.2.1). The new and updated categories are detailed below. Software and Platform Development Under the new promotion policy, the BOI has made separate subcategories for “development” and “improvement” of software or platforms, each with its own set of incentives. The BOI is expected to clarify the characteristics of these two activities in a forthcoming announcement. Qualifying development activities are eligible for a corporate income tax (CIT) exemption for eight years (capped), while improvement activities are not eligible for any CIT exemption. A number of adjustments have been made to the eligibility criteria for development of software and platforms for digital services or content. These include the following: Salary expenditures for Thai information technology (IT) personnel hired temporarily after applying for investment promotion can now be included in the calculation of total salary expenditures for Thai IT personnel hired subsequent to applying for investment promotion. Previously, only salary expenditures for permanently employed personnel could be included in this figure. The minimum salary expenditures for each project remain unchanged at THB 1.5 million per year. Similarly, salary expenditures for temporary hiring of Thai IT personnel can be included in calculating the actual expenditures in the year that the project would like to benefit from the CIT exemption. Projects must commence operations within 12 months of the promotion certificate being issued. No extensions are allowed. Projects are no longer allowed to extend the machinery importation period. The other eligibility criteria for development of software and platforms for digital services or content remain unchanged. Projects in the new BOI subcategory for