You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2024

Vietnam Releases First Draft of New Personal Data Protection Law

On September 24, 2024, the government of Vietnam issued the first draft of a new Law on Personal Data Protection (“Draft PDPL”). As foreshadowed in our previous legal update, the Ministry of Public Security has been very active in developing this draft law. With this draft, they promise to continue their considerable efforts to establish a robust personal data protection culture in Vietnam, as the Draft PDPL indicates a tentative entry into force on January 1, 2026.

With a tentative adoption by the National Assembly in May 2025, the Draft PDPL does not include any transition period, save for micro-enterprises, SMEs, and startups, which are only exempted from appointing a data protection department in their first two years of existence, while the timeline to comply with other obligations under the PDPL remains the same as for other enterprises.

The Draft PDPL includes 68 articles, divided into seven chapters, making it more extensive than last year’s Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), and expressly addresses personal data protection in many fields, including marketing services, behavioral advertising, big-data processing, AI, cloud computing, labor monitoring and recruitment, financial and credit information, health and insurance, and others.

It remains unclear how the PDPL will interact with the PDPD (whether it will replace its predecessor or coexist with it), although the Draft PDPL provides that it will prevail over any laws that have provisions on personal data protection that differ from the provisions of the PDPL.

Among the important new developments of the Draft PDPL when compared to the PDPD, we note:

  • Consent remains the main legal basis for processing, with limited exceptions (still not including “legitimate interest”). However, consent for cross-border transfer is further regulated under the Draft PDPL, including for intra-group sharing.
  • Data processing impact assessment dossiers for controllers and processors (“DPIA”) and transfer impact assessment for transferors (“TIA”) are retained, but, for the latter, the cases of transfer of personal data abroad have been further defined. These DPIAs and TIAs will have to be updated and submitted again to the authorities every six months or immediately upon material change.
  • New definitions have been inserted, such as “developers”, “personal data protection organization”, “personal data protection expert”, “de-identification of personal data”, “use of personal data for marketing”, “use of personal data for behavioral advertising”, and “personal data protection credit rating”, and other definitions currently found in the PDPD have been modified (e.g., land use right-related information has been included as “sensitive information”).
  • A data protection department must be appointed for basic personal data processing (it is no longer limited to sensitive personal data processing) and the Draft PDPL includes a recognition that a data protection department can be an external service provider (i.e., a personal data protection organization). The Draft PDPL further regulates this new service.
  • Certification mechanisms are introduced as credit ratings for personal data protection (high credibility, trust, pass, failing).
  • The 72-hour timeline to address certain data subjects’ requests and to notify the authorities in case of violation of the personal data protection regulations remains unchanged.

We will publish a deeper dive into the Draft PDPL shortly to provide you with more information on this new draft and draw comparisons with the PDPD, which was just enacted last year. [EDIT: Please see “Vietnam’s Draft Personal Data Protection Law: An In-Depth Look.”] Businesses are strongly encouraged to continue monitoring the development of this new legislation for preparation and to provide comments during the public consultation phase, which is open until November 24, 2024.

RELATED INSIGHTS​ 

April 28, 2025
In recent years, Vietnam has positioned itself among the leading countries in the world in terms of digital asset ownership and trading volume. This rapid adoption reflects the country’s growing digital economy and the increasing engagement of individuals and businesses in blockchain-based financial activities. Central to this growth are Resolution No. 57-NQ/TW of the Politburo dated December 22, 2024, on breakthroughs in science, technology, innovation, and national digital transformation with a vision to 2045 (“Resolution 57”) and Resolution No. 03/NQ-CP of the Government dated January 9, 2025, promulgating the Action Plan to Implement Resolution 57 (“Resolution 03”), which outline a flexible and innovative policy framework that embraces pilot programs for emerging technologies to lay the groundwork for Vietnam’s legislative framework concerning cryptocurrency and blockchain technologies. Regulatory clarity in terms of digital assets and blockchain technologies is now more critical than ever for businesses and investors. In light of this, Vietnam is currently in the process of introducing three key legal instruments, with drafts of the Law on Digital Technology Industry (“Draft DTI Law”), Resolution of the National Assembly on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Financial Center Resolution”), and Resolution of the Government on the Pilot Implementation of Crypto Asset Markets in Vietnam (“Draft Crypto Pilot Resolution”) nearing promulgation. Current Regulatory Direction and Schedule Vietnam’s regulatory framework for crypto assets and blockchain has been in a developmental stage since 2017, focusing on directions, plans, and schedules rather than established regulations. In February 2024, under Decision No. 194/QD-TTg of the Prime Minister, the Ministry of Finance (MOF) was assigned to draft a legal framework to either prohibit or regulate virtual assets and service providers by May 2025, signaling a clearer regulatory direction. In March 2025, Directive No. 05/CT-TTg of the Prime Minister directed the MOF
April 18, 2025
On April 12, 2025, Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in the Government Gazette, with the regulation taking effect the following day. Drafts of the amendment had been shared in recent months, and the final amendment of the decree contains some additional key revisions, such as narrowing the business operators subject to the decree’s requirements, reducing operators’ obligations, and establishing collaboration between relevant stakeholders to tackle technology crime. These key revisions to the amendment are detailed below. Business operators subject to the decree: The business operators covered under the decree now include only payment service providers under the Payment System Act and digital asset operators under the Royal Decree on Digital Asset Businesses. Digital platform services under the Royal Decree on Digital Platform Service Businesses That Are Subject to Prior Notification are no longer within the scope of the decree. Definition of technology crime: The final version of the amendment removed the expanded definition of technology crime that had been included in a previous draft, leaving the decree’s existing definition unchanged. Telecommunications provider obligations: Mobile and telecommunications service providers now have an obligation to monitor and screen for content that may be related to technology crime and suspend SIM cards when instructed to do so by the National Broadcasting and Telecommunications Commission (NBTC). Transaction and account suspension: The amendment removes the decree’s complex transaction suspension procedures and leaves room for business-specific regulators (e.g., Bank of Thailand, Securities and Exchange Commission, NBTC) to impose various technology crime suspension requirements on business operators under their supervision. The newly established Center for Prevention and Suppression of Technology Crimes can also notify financial institutions and business operators of names or digital asset wallet addresses that may be related to technology crime,
April 18, 2025
On April 12, 2025, Thailand issued an amended digital asset regulation that covers offshore digital asset businesses providing services on a cross-border basis to Thai users. These businesses will now be subject to the licensing requirements of the Royal Decree on Digital Asset Business Operations B.E. 2561 (2018), which is supervised by Thailand’s Securities and Exchange Commission (SEC). A digital asset business will be deemed as providing services in Thailand—and therefore subject to requirements under the Royal Decree on Digital Asset Business Operations—if the business does any of the following: Displays content in Thai, either fully or partially; Is registered under a “.th,” or “.ไทย” domain, contains any name relating to Thailand, or uses a domain written in Thai characters; Allows or requires payments in Thai baht (THB) or receives payments through Thai bank accounts or e-wallets; Chooses Thai law to govern transactions or Thai courts to litigate any dispute; Pays online search engines to attract users in Thailand to its services; Has an office, establishment, or personnel in Thailand to support or assist users within the country; or Meets any other criteria specified by the SEC. To operate legally in Thailand, offshore operators meeting any of the above criteria will be required to incorporate a local company in Thailand in order to apply for a digital asset business license with the SEC.
April 11, 2025
Vietnam’s draft Personal Data Protection Law (PDPL) continues to evolve, with significant implications for businesses operating in the region. The latest draft, released to the public in March 2025, contains several noteworthy changes from the previous draft that businesses with operations in Vietnam should be aware of when developing their data protection strategies and compliance frameworks. The draft PDPL will be submitted to the vote of the National Assembly in May 2025 with a tentative entry into force on January 1, 2026. Key Changes in the Latest Draft PDPL 1. Redefined Categories of Personal Data The draft PDPL has made important revisions to personal data classifications: Basic personal data: An individual’s image is no longer classified as basic personal data. Sensitive personal data: Bank account information has been removed from this classification (and is now considered basic personal data), but two new categories have been added: (i) salary, allowances, and other income sources, and (ii) information on land users and information on land containing such information. Organizations should review their data classification schemes and update protection measures accordingly, particularly for salary and compensation information. 2. Data Encryption Requirements The draft PDPL explicitly states that encrypted data remains classified as personal data. Additionally, it mandates that sensitive personal data must be encrypted when stored, transmitted, received, or shared in cyberspace. Organizations and individuals can freely opt for one or more encryption solutions and encryption/decryption processes suitable for their personal data management and administration activities. 3. Biometric Data Processing The latest draft PDPL adds new protection requirements for biometric data. Organizations processing biometric data (such as fingerprints) must: Implement physical security measures for devices storing and transmitting biometric data. Use strong encryption methods during transmission and storage. Restrict access to biometric data. Have early-detection monitoring systems to detect violations of biometric