You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 5, 2023

Vietnam’s Data Protection Regulations: What to Expect in 2023

Data protection in Vietnam has been an ever-changing area of law in the last few years, with many legislative and practical developments. From its initiative to build the very first comprehensive Personal Data Protection Decree to meet international standards, to its actions to tackle widespread illegal data processing and trading, the Vietnamese government has shown its determination to strengthen the protection of data, which it has recognized as one of the national key tasks in the Prime Minister’s Strategy for Development of E-Government.

The year 2023 is expected to be another year of many important changes made to the law and practices in this area. This article discusses what we anticipate to be the key upcoming developments in Vietnam’s data protection regime that businesses may wish to keep a close eye on to ensure compliance.

Tightened Rules on Data Collection and Data Transfer

The conditions for personal data processing under the current law are rather sketchily outlined. In general, the data subject’s consent to the scope and purposes of the data processing may be considered sufficient for any collection, use, retention, or sharing of personal data. Explicit consent is not clearly required, except when the data is collected in e-commerce, used for direct marketing purposes, or for other strictly controlled activities. This leads to the practice where data controllers usually do not treat consent as a serious matter. In addition, once consent has been obtained, data controllers tend to comfortably collect whatever data they want, since the law does not require the collection to be “proportionate.”

This situation is expected to change in 2023 with more stringent regulations on personal data processing underway. The first and most influential set of rules on data protection to come out early this year will likely be the much talked-about Personal Data Protection Decree (“PDPD”) developed by the Ministry of Public Security (MPS), which has been in draft form since early 2021. The first public version of the draft PDPD (dated February 2021) proposed ruling out silence by data subjects as a valid form of consent, as well as requiring consent to be expressed in writing with a printable and reproducible format.

These new requirements, once taking force, could render illegal any processing of personal data without explicit consent. Other conditions of consent include that it can be made partially and conditionally, and withdrawn at any time by the data subject. In addition, the draft PDPD also proposed introducing the principle of data minimization (proportionality), according to which personal data collected must be limited to only what is necessary to accomplish the specified purposes.

The Draft Amended Consumers Protection Law (“Draft CPL”), scheduled to be promulgated within 2023, has also proposed tightening the conditions on consent for processing of consumers’ personal data. The Draft CPL requires traders, in obtaining consent for collecting consumer data, to establish a mechanism for consumers to select the types of information that they agree for the traders to collect and express their consent in a suitable form. For special processing purposes like sharing, disclosure, or transfer of personal data to third parties, and use of personal data for sending advertisements and introducing products, the Draft CPL requires a mechanism for the data subjects to clearly opt in to giving or not giving their consent. This requirement is similar to what is currently required for e-commerce websites/applications. In addition, bundled consent, i.e., a clause in a consumer contract or general terms and conditions that makes the conclusion of the contract or the terms and conditions dependent on the consumer’s consent to the collection, storage, and use of his or her data, is likely to be invalid under the Draft CPL.

Interestingly, the Draft CPL provides that collection of personal data that has been publicly disclosed does not require any notification to the consumers. This means scraping of publicly available personal data might be acceptable in Vietnam once the Draft CPL is promulgated and takes effect. However, scraping of non-publicly available personal data is still prohibited and could constitute a crime.

Apart from consent, the regulations on cross-border transfer of personal data will also soon be strengthened. The potential new approach to regulate cross-border transfer of personal data is believed to be revealed by chance in the Draft Decree on Sanctioning Administrative Violations in the Field of Cybersecurity (dated September 2021), which stipulates violations against the draft PDPD. Accordingly, the newly proposed conditions for cross-border data transfer may include only an impact assessment dossier for the transfer, a data transfer agreement between the sender and the recipient, and a post-transfer report to the personal data protection authority.

Compared to the onerous set of conditions for cross-border transfer of personal data that the MPS originally proposed in the draft PDPD, which include among others a state approval prior to the transfer and the storage of the original data in Vietnam, the new conditions appear less burdensome.

Intensified Regulatory Scrutiny

Despite the data protection regulations in place, reports on actual enforcement in practice have been rather limited. One possible reason is that regulatory inspectors have not been focusing on personal data in their activities. Things may change shortly with the recent message from the Ministry of Information and Communications (MIC) on its enforcement plan in this area (source).

In particular, the minister of the MIC announced that the MIC would conduct comprehensive inspections into companies’ compliance with the regulations on collection, processing, and protection of customers’ personal data in the coming time. Telecommunications carriers are said to be the first enterprises to be inspected, followed by postal companies and social networking platforms.

The issue of consent for data processing was notably highlighted by the minister in his discussion. Therefore, compliance in obtaining customer consent can be anticipated to be key in the MIC’s inspection scope. The implementation of technical and managerial measures to protect personal data according to the law is also likely to be scrutinized.

Continued Assertive Action against Illegal Data Trading

Vietnam has for years been a hotspot for the unauthorized trading of personal data, according to recent reports by the MPS and the MIC. The most common violation is where the infringing companies or their employees sell packages of customers’ identity and contact information including phone numbers, email addresses, and ID card information to third parties without authorization. Most of these data buyers would use the personal information for marketing purposes, including to make advertising calls or to send spam SMS or email advertisements to the information subjects. The violators may even use the personal data to commit financial fraud, including to obtain bank loans under the name of the data subject victims, or to impersonate state authorities or acquaintances of the victims to request money transfers (source). Data crimes therefore have been and will continue to be under the enforcement focus of the high-tech police at both the central and provincial levels.

The police are also likely to take a strict view and initiate a criminal prosecution against any act of illegal data trading. The most recent actions reported in the media include two cases where the police of Phu Tho Province prosecuted five individuals for the criminal act of “trading, exchanging, giving […] lawfully private information of an organization or individual on the computer or telecommunications network without the consent of the information owner” under Article 288 of the Criminal Code.

In one of the cases, two individuals were found using self-developed software to collect personal data of over 2 million people by scanning and capturing the data from Facebook and Google accounts, and selling the data. The other case involved three individuals’ collection and sale of more than 400,000 personal information records containing phone numbers and addresses, generating about VND 1.1 billion (approx. USD 47,000) from the illegal business (source). With the government’s determination to tackle data crimes, more criminal actions like these are expected to be seen in 2023.

RELATED INSIGHTS​ 

March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing
March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria