You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2024

Vietnam Releases First Draft of New Personal Data Protection Law

On September 24, 2024, the government of Vietnam issued the first draft of a new Law on Personal Data Protection (“Draft PDPL”). As foreshadowed in our previous legal update, the Ministry of Public Security has been very active in developing this draft law. With this draft, they promise to continue their considerable efforts to establish a robust personal data protection culture in Vietnam, as the Draft PDPL indicates a tentative entry into force on January 1, 2026.

With a tentative adoption by the National Assembly in May 2025, the Draft PDPL does not include any transition period, save for micro-enterprises, SMEs, and startups, which are only exempted from appointing a data protection department in their first two years of existence, while the timeline to comply with other obligations under the PDPL remains the same as for other enterprises.

The Draft PDPL includes 68 articles, divided into seven chapters, making it more extensive than last year’s Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), and expressly addresses personal data protection in many fields, including marketing services, behavioral advertising, big-data processing, AI, cloud computing, labor monitoring and recruitment, financial and credit information, health and insurance, and others.

It remains unclear how the PDPL will interact with the PDPD (whether it will replace its predecessor or coexist with it), although the Draft PDPL provides that it will prevail over any laws that have provisions on personal data protection that differ from the provisions of the PDPL.

Among the important new developments of the Draft PDPL when compared to the PDPD, we note:

  • Consent remains the main legal basis for processing, with limited exceptions (still not including “legitimate interest”). However, consent for cross-border transfer is further regulated under the Draft PDPL, including for intra-group sharing.
  • Data processing impact assessment dossiers for controllers and processors (“DPIA”) and transfer impact assessment for transferors (“TIA”) are retained, but, for the latter, the cases of transfer of personal data abroad have been further defined. These DPIAs and TIAs will have to be updated and submitted again to the authorities every six months or immediately upon material change.
  • New definitions have been inserted, such as “developers”, “personal data protection organization”, “personal data protection expert”, “de-identification of personal data”, “use of personal data for marketing”, “use of personal data for behavioral advertising”, and “personal data protection credit rating”, and other definitions currently found in the PDPD have been modified (e.g., land use right-related information has been included as “sensitive information”).
  • A data protection department must be appointed for basic personal data processing (it is no longer limited to sensitive personal data processing) and the Draft PDPL includes a recognition that a data protection department can be an external service provider (i.e., a personal data protection organization). The Draft PDPL further regulates this new service.
  • Certification mechanisms are introduced as credit ratings for personal data protection (high credibility, trust, pass, failing).
  • The 72-hour timeline to address certain data subjects’ requests and to notify the authorities in case of violation of the personal data protection regulations remains unchanged.

We will publish a deeper dive into the Draft PDPL shortly to provide you with more information on this new draft and draw comparisons with the PDPD, which was just enacted last year. [EDIT: Please see “Vietnam’s Draft Personal Data Protection Law: An In-Depth Look.”] Businesses are strongly encouraged to continue monitoring the development of this new legislation for preparation and to provide comments during the public consultation phase, which is open until November 24, 2024.

RELATED INSIGHTS​ 

February 3, 2025
On January 28, 2025, the Office of the Personal Data Protection Committee (PDPC) hosted Data Privacy Day 2025, bringing together over 1,000 participants from both the public and private sectors. The event underscored the importance of personal data protection and aimed to raise nationwide awareness while fostering a culture of compliance. During the event, the PDPC reaffirmed its commitment to strengthening Thailand’s data protection framework to align with international standards. The initiative also emphasized the collective goal of achieving zero data breaches. During the first session of the event, Mr. Prasert Jantararuangtong, deputy prime minister and minister of digital economy and society, delivered a speech highlighting the role of personal data protection in fostering Thailand’s digital economy. He emphasized that strong data protection measures enhance business credibility, build consumer trust, and attract foreign investment. He also addressed the PDPC’s “zero data breach” policy and the ongoing issue of data leaks, which have been exploited by call-center scam operations to deceive the public and cause financial harm. Additionally, Mr. Prasert announced that the Thai cabinet has approved a draft amendment to the Emergency Decree on Cyber Crime Prevention and Suppression B.E. 2566 (2023), commonly referred to as the “Cyber Crime Decree.” The draft will now proceed to the Council of State for review before its official enactment. Key provisions of the amendment include holding financial institutions, telecom providers, and social media platforms accountable for technology-related crimes; requiring compensation for victims; and enforcing stricter security measures. Cyber offenses, including personal data trading, face harsher penalties of up to THB 5 million in fines or five years of imprisonment. Authorities are also empowered to suspend suspicious SIM cards for committing illegal activities and expedite monetary refunds for victims without court approval. In the second session, the Office of the PDPC presented its
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 24, 2025
Following Vietnam’s adoption of the new Law on Data (“Data Law”) on November 30, 2024, there remained uncertainty as to what impact the new framework would have on businesses in Vietnam and abroad. The government has now released a package of four draft legal documents aimed at guiding the implementation of the Data Law: (1) a decree on the National Data Development Fund (“NDDF Decree”), (2) a decree related to regulations on scientific, technological, and innovation activities and data products and services (“Decree on Specific Activities”), (3) a decree detailing a number of articles and measures to implement the Data Law (“Implementation Decree”), and (4) a decision on the lists of important data and core data. This article will provide an overview of the draft legislation. 1. NDDF Decree The draft NDDF Decree relates to the establishment, management and use of a National Data Development Fund (“NDDF”), which is a non-profit and non-budgetary state financial fund established and managed by the Minister of the Ministry of Public Security (MPS). The NDDF has legal personality and is fully state owned, operating similarly to a single-member limited liability company. Its main objectives are to support, promote, and invest in artificial intelligence (AI), the Internet of Things (IoT), and other new technologies and innovation. The NDDF may lend to, invest in, or otherwise support eligible organizations. The draft NDDF Decree also proposes a series of regulations on donations to the NDDF and from the NDDF (through expense support), the lending activities of the NDDF to commercial banks, which will in turn lend to eligible organizations, the investment activities in data products and services innovative start-ups, and other kinds of support. The government commits to provide VND 1 trillion (approx. USD 40 million) to the NDDF, evidencing the importance the government places on
January 23, 2025
Thailand’s Ministry of Digital Economy and Society, through the Digital Economy Promotion Agency (DEPA), recently held a focus group hearing on the draft Gaming Industry Promotion Act. This legislation seeks to strike a balance by promoting the growth of the online game industry while safeguarding society, with a particular focus on protecting youth from potential negative impacts and enhancing a positive gaming environment. From the public releases, the draft act is expected to address several key aspects, including: Registration requirements for key industry players, such as developers and platform providers. It is also worth monitoring whether these requirements will also apply to offshore entities offering services to users in Thailand. Governance measures, such as game rating systems and measures to address online gambling and violence in games. Incentives, such as the establishment of a fund to support the gaming industry, and tax incentives to promote Thai gaming businesses. DEPA plans to incorporate feedback from the focus group hearing to refine the Draft Act. The legislation is expected to be submitted to the cabinet for approval by April 2025, with enactment expected by the end of 2025. As this draft law is still at an early stage, amendments may be introduced during the legislative process. Businesses and stakeholders in the gaming industry are encouraged to monitor the matter closely and assess how the developing legislation may impact their operations.