Business marketing activities must adapt their strategies to comply with personal data protection law in Vietnam

Insights
Business marketing activities must adapt their strategies to comply with personal data protection law in Vietnam
Posted on: 23/10/2025

    For many businesses, in the coming time, marketing activities must be reviewed and shaped new strategies to comply with the new legal framework on personal data protection that Vietnam has issued in 2025. Many new, complex and far-reaching requirements will place many responsibilities on the shoulders of businesses that are not very easy.

     

     

    1. New legal framework for personal data protection

    1.1. From Decree 13 to the Law on Personal Data Protection 2025

    The legal framework for personal data protection in Vietnam is undergoing a highly institutionalized transformation, from Decree 13/2023/ND-CP (PDPD) upgraded to the Law on Personal Data Protection (PDP). Decree 13, effective from July 1, 2023, has laid the first foundation for the management and processing of personal data, defining the roles and rights of data subjects and the responsibilities of relevant organizations and individuals.

    Next, the National Assembly passed the Personal Data Protection Law (PDPL 2025), on June 26, 2025, which is expected to officially take effect from January 1, 2026. The PDPL Law 2025 serves to consolidate and strengthen privacy regulations that are scattered in various legal documents, establishing a more unified and robust legal framework to protect people's personal data.

    The upgrade from a Decree to a Law shows Vietnam's long-term commitment and special attention to privacy in the digital era. This is no longer a temporary regulation but a foundational legal framework, which has a far-reaching impact on all business activities, especially marketing and communication activities that depend on data. This implies that businesses must shift from a response mindset to a compliance mindset right from the system design stage into management tools, because the risk of sanctions will increase significantly when the Law officially takes effect.

    1.2. New definitions of personal data

    The PDP Law 2025 maintains a broad, extraterritorial scope of application, similar to Decree 13. The Law applies to Vietnamese agencies, organizations and individuals, and more importantly, foreign agencies, organizations and individuals directly involved in or related to personal data processing activities in Vietnam. This covers all multinational companies or global technology platforms that are collecting data of Vietnamese citizens.

    Personal data is defined as information in the form of symbols, letters, digits, images, sounds, or similar forms in the electronic environment that is associated with a specific person or helps to identify a specific person. Personal data is categorized into basic data and sensitive data.

    In the chain of personal data processing, enterprises must clearly define their legal roles, including:

    The Data Controller (decides the purpose and manner of the processing), the Data Processor (the Controller's contractual processing), or the Data Controller and Processor. In a marketing environment associated with technology and data, businesses that use customer data governance platforms are often data controllers, while platform providers act as Data Processors.  

    This classification of roles creates the challenge of shared responsibility in the technology-linked marketing ecosystem. Businesses as Controllers are primarily responsible for the purposes of the processing, but Processors as service providers are also obliged to comply with data protection measures. This requires businesses to review and update their Data Processing Agreements (DPAs) with all marketing service providers to ensure they have sufficient commitments and provide the necessary tools for compliance, such as consent management and data erasure tools. If a breach occurs on the part of the Processor, the Controller may still be held liable for failing to perform the necessary due diligence and supervision obligations.

    2. The new legal framework has a direct impact on marketing data collection and processing strategies

    2.1. The forced shift to a new marketing paradigm

    Consent regulations are the most fundamental change, requiring marketing teams to change the entire process of collecting and building customer databases. Vietnam's Personal Data Law stipulates that the consent of the data subject must be clearly and specifically expressed in recognizable forms such as text, voice, ticking the consent box, consent syntax via SMS, or selecting consent technical settings.  

    This consent must ensure voluntariness and the data subject must be aware of the contents of the personal data processing notice before approving. In particular, consent must be conducted for the same purpose of processing. This requirement removes most of the implicit consent or default set consent (pre-checked consent box) that is common in traditional marketing.

    This strictness places a huge burden of recording consent to prove accountability when the authorities check, businesses must record and store clear and detailed evidence of consent.

    As a result, marketing teams had to redesign the entire data collection interface, from websites to mobile apps, integrating a customer consent management platform to record timestamps and consent content. While conversion rates may decrease due to a clear request for action from users, the data quality and legitimacy of the customer database will be strengthened.

    2.2. Obligation to notify and manage customer data of enterprises

    The obligation of businesses to be transparent in information is significantly enhanced when PDPL 2025 comes into practice. The Data Controller and the Data Controller and Processor must notify the subject of the processing of personal data once before proceeding with the processing. The content of the notification must be detailed, including: (1) Purpose of processing, (2) Type of data used, (3) Method of processing, (3) Information about the parties involved, (4) Possible consequences and unintended damages, and (5) Time for starting/ending data processing.

    In addition, businesses must develop a mechanism for data subjects to exercise their rights. Decree 13 and also PDPL 2025 stipulate 10 basic rights, of which, the two rights that have the greatest impact on corporate marketing activities are: The right to withdraw consent and  the right to delete data.

    If the subject withdraws consent, the business is forced to stop processing the data immediately. Continuing the unauthorized processing of data after the subject has withdrawn consent is a serious violation and can be fined, even up to 5% of total revenue.

    The requirement to enforce these rights poses a serious challenge to the speed and integrity of the system. The right to withdraw and delete data requires businesses to be able to identify, isolate, and delete an individual's personal data from all storage and processing systems (including CRM, CDP, Data Warehouse, and Email Marketing lists) quickly and thoroughly. Legacy, fragmented, or inadequately integrated marketing systems will not be able to meet this requirement, creating a major compliance gap. Businesses need to invest in a centralized data management system that is capable of data encryption, access control, and integration of automatic data deletion/anonymization mechanisms.

     

    Managing Partner Nguyen Van Phuc, HM&P Law Firm participated in the corporate training session. Source: The Saigon Times

     

    3. Risks in the process of complying with the new legal framework on personal data protection

    3.1. Strict sanctions of PDPL 2025

    Vietnam's PDPL 2025 has issued regulations on strict sanctions for enterprises if they violate regulations on personal data protection.

    The most severe penalty can be up to 5% of the previous year's gross revenue. This fine is applied to serious violations or repeat violations of key regulations, including: violations of the principles of personal data protection (Article 3); violating regulations on consent of data subjects (Article 11); or continue to process personal data illegally after the data subject has withdrawn consent (Article 12).  

    For marketing activities, violations of regulations on personal data protection in marketing and advertising can also lead to fines, suspension of marketing activities, and especially a fine of up to 5% of total revenue for repeat or serious violations.

    In addition to the revenue-based penalty, there are other penalty brackets such as a fine of up to 10 times the illicit revenue or a maximum fine of up to VND 3 billion. Additional consequences can include forcing businesses to revoke, destroy illegally collected data, forced remediation, suspend data processing activities, or even prosecute criminal liability in extremely serious cases.

    A fine of 5% of gross revenue is equivalent to a maximum level 2 fine of the European General Data Protection Regulation (GDPR), creating systemic risks and reputational crises for businesses operating in cyberspace. In the digital economy, violations are often massive, such as system failures that collect millions of invalid records. If the processing of personal data is suspended, the ability of businesses to interact with customers will be paralyzed, leading to a loss of market share and a heavy loss of brand reputation.

    4. Challenges in cross-border data transfer activities of enterprises

    4.1. Strict regulations on the transfer of personal data abroad

    Article 25 of Decree 13 as well as in PDPL 2025 stipulates strict requirements for the transfer of personal data abroad. This is the biggest challenge for Vietnamese businesses using modern marketing tools related to the Cloud, or CRM with servers located outside the territory.

    The definition of cross-border data transfer is very broad, not only the transfer of personal data of Vietnamese citizens to a location outside the territory, but also the processing of personal data of Vietnamese citizens using automated systems located outside the territory. This covers most of the global Cloud SaaS services used for marketing.

    The core requirement is that the Data Transferor must prepare a Personal Data Transfer Abroad Impact Assessment (CBDA) and submit it to the Ministry of Public Security (Department of Cyber Security and High-tech Crime Prevention and Combat - A05) within 60 days from the date of data processing. The CBDA dossier is a complex legal and technical document that must describe in detail the purpose of the processing, the type of data, the protection measures, the risk assessment, the consent of the subject, and the commitment to bind the responsibilities between the transferor and the recipient.  

    This requirement to prepare and update CBDA records creates a large administrative burden and cost on the business. Companies that use various international cloud platforms such as Salesforce services, Hubspot, or data analytics services on AWS/Azure will have to repeat this process for each personal data transfer relationship.

    The Ministry of Public Security has the right to inspect normal data transfer activities 01 time/year and has the right to decide to request the data transferor to stop the data transfer if it is detected to violate national interests and security, fail to comply with the requirements for completion of dossiers, or allow disclosure incidents to occur.  loss of personal data of Vietnamese citizens. This power to inspect and suspend operations creates a serious risk to the business continuity of the enterprise.

    4.2. Impact of new regulations on the use of international marketing platforms

    Regulations on cross-border data transfers in marketing activities directly affect tech giants and Vietnamese businesses that depend on these platforms. Platforms that dominate the advertising market such as Meta (Facebook) and Google (YouTube), with tens of millions of Vietnamese users and large advertising revenues, bear disproportionate compliance costs. They must establish a specialized compliance infrastructure and continuously update the audit record for their global operation in relation to Vietnamese users.

    For Vietnamese businesses, any activity related to targeted ads or analysis of customer data stored on a foreign server can be considered as an activity of processing personal data using an automated system located outside the territory of Vietnam. If the Ministry of Public Security finds that Meta or Google does not comply with the regulations on updating records or allows data incidents to occur, they can request to stop transferring/processing data, disrupting marketing activities of Vietnamese businesses.

    Major Cloud providers such as Google Cloud have emphasized that customers own the data and have granular control through access management tools (Cloud IAM) and data erasure rights. However, the Data Controller is still ultimately responsible for ensuring compliance when transferring, including the recording of mandatory processing logs.

    To minimize the risk of international marketing suspension and the burden of assessing cross-border personal data transfers, a data partitioning and disinfection strategy is deemed necessary. Sensitive data or original data of Vietnamese citizens should be processed and stored initially on domestic infrastructure or domestic Cloud solutions that meet security standards. Enterprises should then only transfer data that has been anonymized/disinfected or aggregated abroad for the purpose of advertising analysis and optimization, in order to significantly minimize legal and administrative risks related to the provisions of Vietnam's personal data protection laws.

     

    Partner Nguyen Ngoc Tra My and Senior Associate Nguyen Nhat Duong, HM&P Law Firm participated in the corporate training session. Source: The Saigon Times

     

    5. Some recommendations for developing a PDPL compliance strategy in marketing activities

    To effectively respond to the impact of PDPL, businesses need to implement a comprehensive transformation roadmap, focusing on restructuring the technical system and strengthening legal governance in the coming time. Focusing on these strategies, HM&P recommends the following solutions to businesses:

    5.1. Restructuring operations and data management

    Establish a consent management platform: Businesses should immediately implement the IT system necessary to collect, record, and store clear evidence of consent for each processing purpose. The system must be closely integrated with customer touchpoints (websites, applications) and support systems such as CRM/CDP to ensure synchronization.  

    Implementation of impact assessment dossiers: The Data Controller must prepare and store the Impact Assessment Dossier on the processing of personal data according to the standard form right from the time of commencement of personal data processing. This dossier is a legal document that must be available to serve the inspection and assessment activities of the Ministry of Public Security.  

    Building a mechanism for implementing the rights of data subjects: Invest in technical tools to ensure the ability to quickly implement the rights of data subjects (delete, withdraw consent, object to processing) in all marketing systems of enterprises. Delays in stopping processing after withdrawing consent can force businesses to be subject to strict sanctions from the competent authorities.  

    Logging and storing system logs: Ensure that the  Controller and the Data Controller and Processor establish a complete and detailed process for recording and storing personal data processing system logs. This is necessary for the purpose of inspection and tracing of violations (if any).  

    5.2. Legal Governance for Compliance

    Appointment of a Personal Data Protection Officer (DPO ): Arrange and appoint a Data Protection Officer (DPO) to monitor compliance, handle requests/complaints of data subjects, and work with authorities.  

    Promulgating and updating internal policies: Develop or review internal regulations on personal data protection, especially customer data processing processes, employee data processing processes, and develop Incident Response Procedures to ensure that violations can be reported within 72 hours.  

    Review and update contracts with partners: Businesses should require all partners and marketing/cloud service providers to commit to complying with PDPL 2025 and include detailed legally binding terms on personal data processing to clarify the roles and responsibilities of each party and have specific commitments to protect customers' personal data.  

    In short, the marketing activities of the business in the coming time will have fundamental changes and adjustments, affecting the entire operation of the business. Accordingly, enterprises need to take steps to review, examine and come up with appropriate strategies to comply with the law on personal data protection in Vietnam. In the process, the involvement of a professional legal consultant is also a necessary solution to mitigate the risks from the impacts of this new legal framework in Vietnam.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm