You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 27, 2025

Vietnam’s New Personal Data Protection Law: A Closer Look

Vietnam officially enacted Law No. 91/2025/QH15 on Personal Data Protection (“PDPL”) on June 26, 2025, marking a major milestone in the country’s legal landscape. While the PDPL retains many provisions from its predecessor, Decree No. 13/2023/ND-CP on Personal Data Protection (“PDPD”), it adds new concepts, exemptions, and compliance obligations. Notably, it sets out a framework regulation for penalties for violations, including monetary fines of up to 5% of the corporate violator’s annual revenue in the previous year for cross-border data transfer breaches.

With an effective date of January 1, 2026, the PDPL will apply to (i) Vietnamese agencies, organizations, and individuals; (ii) foreign agencies, organizations, and individuals in Vietnam; and (iii) foreign agencies, organizations, and individuals directly involved in or related to the processing of personal data of Vietnamese citizens and persons of Vietnamese origin without a determined nationality, currently residing in Vietnam, who have been granted a personal identification certificate.

Although the PDPL does not explicitly define its relationship with the currently effective PDPD, the government is drafting a new decree to guide the PDPL’s implementation, the first draft of which is expected to be completed by September 2025, with an effective date aligned with that of the PDPL. Once both the PDPL and its implementing decree come into force, the PDPD will presumably cease to have legal effect. [Update: Decree No. 356/2025/ND-CP detailing and guiding the implementation of the PDPL was issued on December 31, 2025, and took effect on January 1, 2026. See our article here.]

Some key takeaways from the PDPL are presented below.

1. Definitions of “Personal Data,” “Basic Personal Data,” and “Sensitive Personal Data”

The PDPL introduces broad definitions for “personal data,” “basic personal data,” and “sensitive personal data.” It expands the scope of personal data to include both digital and non-digital formats, such as paper-based records. Notably, de-identified personal data is explicitly excluded from the definition of personal data. The PDPL further delegates authority to the government to issue exhaustive lists specifying which types of data qualify as basic and sensitive personal data. These lists are expected to be detailed in the PDPL’s implementing decree.

2. Data Subjects’ Rights and Obligations

The PDPL retains the rights of data subjects as previously outlined in the PDPD, with clarifications of the rights themselves and certain strengthened procedural requirements. In addition to the data subjects’ rights, the PDPL imposes specific obligations on data subjects, including the obligations to:

  • Self-protect their own personal data;
  • Honor and protect others’ personal data;
  • Provide adequate and accurate personal data according to applicable laws and regulations, contracts, or consent given to the processing of their own personal data; and
  • Comply with the personal data protection laws and regulations and participate in the prevention of personal data infringements/violations.

These provisions are designed to prevent misuse of personal data rights and promote a culture of shared responsibility in the digital environment, while reinforcing individuals’ control over their own data.

3. Personal Data Trading and Transfer

The PDPL strictly prohibits the sale and purchase of personal data, except as otherwise prescribed by the law. This prohibition is part of a broader effort to combat the widespread illegal online trading of personal data and prevent insider abuse. Violations of this provision may result in severe penalties, including fines of up to 10 times the revenue gained from the unlawful act of personal data trading.

The PDPL provides clarification, however, that certain types of data transfers do not constitute the “sale and purchase of personal data.” These include:

  • When the data subject has given consent.
  • When data is shared between departments within the same agency or organization for processing in line with the determined purpose.
  • When data is transferred for continued processing due to the division, separation, or merger of agencies, organizations, or administrative units; the reorganization or transformation of ownership of state-owned enterprises; the division, separation, merger, consolidation, or dissolution of entities or organizations; or the establishment of entities or organizations based on the dissolution of other entities or organizations.
  • When the data controllers or data controller-processors transfer data to a data processor or third party (e.g., independent data controllers) for processing as prescribed.
  • Upon request from competent state authorities.
  • In circumstances where personal data can be processed without the data subjects’ consent as prescribed under the PDPL (see item 5 below).

These exceptions are expected to be further detailed in the PDPL’s implementing decree.

4. Maximum Administrative Sanctions for Violations

In addition to the maximum fine for illegal personal data trading, the PDPL sets the maximum administrative fine on an organization for violations related to cross-border personal data transfers at 5% of the violator’s revenue in the preceding fiscal year. In cases where the organization has no revenue in the preceding year, or where the fine calculated based on such revenue is lower than VND 3 billion (approx. USD 114,500), the latter will apply. The maximum administrative fine for other violations in the field of personal data protection is VND 3 billion. The method to calculate revenue arising from violation of personal data protection regulations will be further prescribed by the government under the PDPL’s implementing decree.

5. Consent Requirements

The consent-centric approach and strict consent formality requirements of the PDPD are maintained in the PDPL, which provides additional cases of consent-exemptions. These include, among others, situations where personal data processing is necessary to protect one’s own legitimate rights or interests, or those of others, as necessary against acts that infringe upon such interests (e.g., legal defense), and the fulfillment of contractual obligations not only of the data subjects but also of the service provider.

While the PDPL uses the term “legitimate interest,” its scope is significantly narrower than under the GDPR, and applies only when data processing is required to prevent infringement by third parties.

For situations where consent is exempted, the PDPL introduces a requirement for the data controllers and relevant data processors to implement a monitoring mechanism to protect the data, including but not limited to implementing appropriate data protection measures and regularly assessing possible risks, periodically inspecting and assessing compliance with the law, and receiving and addressing feedback and petitions from relevant parties.

The PDPL includes a transition clause allowing personal data processing activities that have been carried out prior to the effective date of the PDPL with the consent of the data subject or based on an agreement in accordance with the PDPD, to continue, without requiring new consent or a new agreement. This provision offers continuity for businesses already compliant with the PDPD, while signaling the need for updated practices that align with the PDPL’s enhanced standards.

6. Data Processing and Data Transfer Impact Assessment

The requirements for the preparation, submission, and maintenance of a Data Processing Impact Assessment (“DPIA”) and a Data Transfer Impact Assessment (“TIA”) under the PDPD are inherited by the PDPL. The PDPL has assigned the government to provide detailed requirements on the dossier, conditions, order, and procedures for each impact assessment in the PDPL’s implementing decree. However, it is anticipated that these requirements will generally align with those outlined in the PDPD.

To reduce the compliance burden, the PDPL makes it optional for small businesses and startups to comply with the DPIA requirements for five years from the PDPL’s effective date, while household businesses and micro-enterprises are exempt. However, entities that provide personal data processing services, directly process sensitive personal data, or process the personal data of a large number of data subjects are not eligible for this exemption.

The PDPL mandates a six-month update cycle for both the DPIA and the TIA if there are any changes. Immediate updates are required in specific circumstances, such as (i) company restructuring, termination, dissolution, or bankruptcy; (ii) change of organization or individual providing personal data protection services; or (iii) introduction of new business lines/activities or changes to the current business lines/activities involving personal data as declared in the DPIA and TIA.

DPIAs and TIAs received by the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security (known as the “A05” department) before the PDPL’s effective date (i.e., January 1, 2026) in accordance with the PDPD will remain valid. However, any updates made to these dossiers made after the PDPL comes into force must comply with the requirements set out under the PDPL.

7. Notification of Violations

One of the key changes introduced by the PDPL is the revised timeline for notification of detected violations. Organizations are now required to report violations within 72 hours of detection, rather than from the time of occurrence as previously mandated under the PDPD. Moreover, while the PDPD only requires notification to the regulator (specifically, the A05), the PDPL expands this obligation to include notifying affected data subjects in cases involving biometric data incidents or incidents related to financial service providers.

8. Special Personal Data Protection Mechanisms

Some special data protection mechanisms are introduced under the PDPL, as follows:

For specific data subject groups: The PDPL sets out enhanced and more comprehensive safeguards for the personal data of vulnerable groups, such as children and individuals with limited or lost civil act capacity, or those with cognitive or behavioral impairments. For instance, the processing of children’s data generally requires only parental consent. However, if the data pertains to the child’s private life or personal secrets, and the child is age 7 or older, dual consent from both the child and the parent must be obtained.

For specific businesses and operational activities: The PDPL outlines tailored safeguards for personal data processing activities across various sectors and operational activities, including employment (recruitment and employee management); health data and insurance business; financial, banking, and credit information activities; advertising services; social network platforms and online communications services; big data processing, artificial intelligence, blockchain, virtual universe and cloud computing; and audio and video recording in public places and public activities. While some provisions are sector-specific, some can be generally applied to all enterprises; for instance, the requirement for deletion/destruction of information provided by job applicants who are not hired, unless there is a different agreement with the applicant.

For specific types of sensitive personal data: Specific safeguards required for processing location and biometric data are also prescribed under the PDPL.

9. Personal Data Protection Department and Personnel

The PDPL requires organizations to either designate a qualified department and personnel dedicated to personal data protection, or engage external data protection service providers. Such personal data protection departments, personnel, and service providers are components of what the PDPL refers to as the “personal data protection forces.”

While the government has yet to issue detailed regulations on “personal data protection forces,” further guidance on the conditions, responsibilities, and tasks of the designated data protection department and personnel are expected in the PDPL’s implementing decree.

Small and startup enterprises are granted a five-year grace period from the PDPL’s effective date to determine whether to comply, while household businesses and micro-enterprises are exempted from this requirement (save for cases where these entities provide personal data processing services, directly process sensitive personal data, or process the personal data of a large number of data subjects).

Outlook

The promulgation of the PDPL represents a major advancement in Vietnam’s legal landscape, reinforcing the existing data protection framework for better safeguarding the privacy and personal rights of Vietnamese citizens in the digital era, and at the same time promoting the digital economy and international integration in the country. Businesses will need to reevaluate and consolidate their data governance practices and internal controls to ensure prompt and effective PDPL compliance. It is also important for businesses to keep an eye on upcoming regulations and guidance to properly implement the PDPL.

RELATED INSIGHTS​ 

March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing
March 16, 2026
Thailand’s Securities and Exchange Commission (SEC) has broadened the definition of institutional investors, expanded the types of qualifying investments, and updated financial qualification thresholds for various investor categories through a revised notification on the definitions of institutional investors, ultra-high net worth investors, and high net worth investors. The amended framework, which came into force on March 1, 2026, adds digital asset business operators, investment planners, and investment consultants to the roster of entities recognized as institutional investors, and broadens the definition of investment to account for digital tokens. Expanded Definition of Institutional Investors Under the SEC’s revised notification, the category of institutional investors now expressly includes digital asset business operators licensed under the Royal Decree on Digital Asset Businesses B.E. 2561 (2018). This addition recognizes the growing role of digital asset platforms and service providers in Thailand’s investment ecosystem and aligns the regulatory treatment of digital markets with that of traditional markets. The definition of institutional investors now also encompasses investment planners and investment consultants approved by the SEC. Previously, only SEC-approved investment analysts held this status; the expansion covers a broader scope of professionals who possess comparable expertise and experience in evaluating investment opportunities. Broadened Investment Definition The revised framework now defines investment to mean direct or indirect investment in a wider range of assets beyond deposits. Specifically, the definition covers: Securities under the Securities and Exchange Act Derivatives under the Derivatives Act Investment tokens offered to the public Government-issued digital tokens (G-tokens) as specified in a separate SEC notification This expansion ensures that financial status assessments reflect the full spectrum of an investor’s holdings, including emerging digital assets. Updated Financial Qualification Thresholds The amended SEC notification also provides updated qualification thresholds for angel investors, ultra-high net worth investors, and high net worth investors. While the core criteria
March 13, 2026
Vietnam’s Law on Intellectual Property (IP Law) has undergone continuous amendment in recent years, with the latest amendment issued at the end of 2025. Among the amended and supplemented provisions, the regulation that has perhaps attracted the most attention is a provision relating to the use of protected IP objects by artificial intelligence (AI) systems. Specifically, Article 7 of the 2025 IP Law introduces a completely new Clause 5, which reads in full as follows: “Organizations and individuals are permitted to use texts and data relating to intellectual property objects that have been lawfully published, and which the public is allowed to access, for the purposes of scientific research, experimentation, and training of artificial intelligence systems, provided that such use will not unreasonably affect the legitimate rights and interests of the authors and intellectual property rights holders in accordance with this Law. With respect to texts and data that are objects protected by copyright and related rights, the use of the texts and data as set forth herein must also be in accordance with the regulations of the Government.” Analyzing this newly added provision in the context of how it was conceived, as well as the challenges that still lie ahead, can provide some interesting insights. From Aspirations to Flight in Science and Technology From the end of 2024 and throughout 2025—the 50th anniversary of the country’s reunification—Vietnam witnessed numerous sweeping changes in many areas, including legislative development. It could be said that no sessions of the National Assembly have ever adopted as many laws, resolutions, and major policies as this one. The aspirations of the highest-level leadership have been concretized into major law and policy projects, which were drafted, developed, and passed at record speed. All of this was aimed at building a foundation for Vietnam to achieve
March 12, 2026
Thailand’s AI legislative framework took another step forward when the Office of the Consumer Protection Board (OCPB) issued a notification establishing guidelines for AI-generated advertising that may cause material misunderstanding about products or services. The notification, which is already in effect, was issued under the Consumer Protection Act B.E. 2522 (1979) and its amendments, which prohibit advertising that is unfair to consumers or may cause harm to society, including false or exaggerated statements and statements that may cause material misunderstanding about products or services. The notification addresses emerging advertising practices, including the use of images edited using software or AI to attract consumer interest or build credibility. The OCPB noted that such advertising may result in consumers misunderstanding the essential characteristics, condition, or usage of products, which violates consumer rights and causes damage. Key Requirements on AI-Generated or Digitally Manipulated Advertising Content For advertisements using still images or videos created or edited with software programs or AI tools that may cause the depicted product or service to differ from the actual product sold or service provided—which may cause misunderstanding regarding the condition, quality, quantity, or other essential aspects of the products or services—advertisers and business operators must comply with the following requirements: Prior authorization. Obtain approval from relevant regulatory authorities where required by law. Accurate representation. Ensure that the advertised size, quantity, volume, number, or composition matches the actual product or service being sold, whether in still images or videos. Mandatory AI disclosure labels. Display clear disclosures when AI or software is used to create or edit images, such as: “Real image or simulation edited using AI” “Photo from actual location or simulation edited using AI” “Photo from actual product or edited simulation” “Image created by AI” “Video created by AI” Clarity of disclosure. Ensure disclosures are clearly visible,