You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 2, 2024

With Illicit Personal Data Trading on the Rise, Vietnam Seeks Solutions

The pervasive global issue of illicit personal data trading has extended its reach into Vietnam, where such sensitive information is being sold at minimal costs. A 2023 report from the Ministry of Public Security revealed that over two-thirds of the Vietnamese population has fallen victim to unlawful data collection and distribution. In the past two years, authorities have pressed charges on five criminal cases involving the buying and selling of billions of items of personal data, encompassing a wide range of sensitive information such as names, phone numbers, email addresses, and more. Notably, a person’s profile can be acquired for just USD 1, while profiles of millions of business customers can be obtained for a mere USD 100.

Recognizing the severity of the problem, Vietnam has made serious efforts to combat illicit personal data trading by criminal means, encompassing both the legal framework and practical implementation.

 

Understanding the Criminal Legal Framework

Vietnam’s 2015 Criminal Code, as amended in 2017, functions as a pivotal legal instrument delineating offenses and their corresponding punishments. Under Section 2 of Chapter XXI of the Criminal Code (“Offenses Against Regulations on Information Technology and Telecommunications Networks”), individuals engaging in the illicit trading of personal data, depending on the nature of the data (e.g., information about phone number, address, or—more dangerously—bank account) and the nature of the infringing acts, may be charged under different crimes. The sanctions can include monetary fines; non-custodial reform; imprisonment; and/or prohibition from holding certain positions, practicing certain professions, or doing certain jobs.

For example, for the illicit trade of private information of an individual on a computer or telecommunications network, Article 288 of the Criminal Code specifies penalties including a monetary fine of up to VND 1 billion (equivalent to around USD 41,000); non-custodial reform of up to three years; imprisonment of up to seven years; and/or prohibition from holding certain positions, practicing certain professions, or doing certain jobs for up to five years.

In the eyes of some scholars and practitioners, these sanctions are an insufficient deterrent, as personal data is deemed highly sensitive and has the potential to substantially affect the individuals involved, as well as pose broader risks to security and public order. However, others would argue that these penalties are relatively harsh in Vietnam, where the average worker makes less than USD 4,000 per year, and could prove to be effective if they are widely and consistently applied in practice.,

 

Handling of Criminal Cases in Practice

In a recent case settled by the People’s Court of Hai Duong Province in December 2022, Mr. K (the offender) collected and distributed 3,848 files containing customers’ data from two financial companies in Vietnam. The total amount Mr. K gained from selling personal information was VND 458,952,000 (approx. USD 18,825).

Considering that Mr. K had full legal capacity for criminal liability and was clearly aware that his act was a violation of criminal law, but still intentionally committed it for personal gain, the People’s Court of Hai Duong Province applied Article 288 of the Criminal Code and ruled that Mr. K was subject to:

  • A suspended sentence of 24 months, with a probation period of 48 months from the date of first-instance decision;
  • A fine of VND 100 million (USD 4,100) to be paid to the state budget;
  • Confiscation of the illicit profits of VND 458,952,000 (USD 18,825) he obtained to be remitted to the state budget; and
  • Confiscation and sale of the exhibits used to commit a crime, comprising one computer desk, one computer hard drive, one USB drive, and one mobile phone, to be remitted to the state budget.

In another case settled by the People’s Court of Hanoi in March 2023, multiple offenders were involved, including, among others, a former police officer, the deputy head of the security department of a network infrastructure company, and an officer of the social insurance authority. The proceeds obtained by each offender from illicit trading of personal data ranged from VND 140 million (USD 5,750) to about VND 500 million (USD 20,550).

After examining all the case facts, the People’s Court of Hanoi imposed penalties ranging from a 20-month suspended sentence to six years of imprisonment, depending on the severity of the crime committed by each offender.

 

Outlook

The buying and selling of personal data in Vietnam remains a significant and growing concern, though the authorities have handled such violations quite severely, as reflected in the case examples above.

In November 2023, the Minister of Public Security, when questioned about the alarming situation of illicit trade of personal data, expressed his deep concern over the prevailing issues of exposure, leakage, and trading of personal information in Vietnam. The minister even proposed amendments to the Criminal Code to incorporate offenses related to disclosing, leaking, buying, and selling personal data, with the aim of enforcing strict penalties for these actions.

It is anticipated that with more stringent regulations and thorough measures in place to be enacted, unauthorized data trading will be effectively curtailed.

RELATED INSIGHTS​ 

March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing