If the Law on Personal Data Protection (Law on PDP) is the "original law" on privacy, the Draft Law on Cyber Security (Amendment - Law on Cyber Security) raises the issue of data protection in the wider cyberspace, while the Draft Law on Artificial Intelligence tackles the new problem of how artificial intelligence systems - which live on data - still respect the rights of children people, privacy, and avoidance of deviance.
On June 26, 2024, the Singapore Personal Data Protection Commission (PDPC) was notified of a data breach involving the company's servers infected with ransomware around June 24, 2024. As a result, the personal data of 190,589 individuals was stolen and posted for sale on the dark web .
The article provides some in-depth opinions on legal risks and expected litigation trends related to personal data privacy in Vietnam in the near future. Especially from January 1, 2026, the time when the Law on Personal Data Protection (Law on PDP) officially takes effect and creates a solid foundation for litigation activities to protect the privacy.
Facing the urgent requirement to effectively manage new technologies and keep up with the world's development trends, Vietnam is gradually building and perfecting a separate legal framework for artificial intelligence. This is not only a necessary step to ensure safety and transparency in the application of artificial intelligence in multiple fields and industries, but also to create a stable legal corridor, promote innovation and support entities to participate in the digital technology ecosystem.
In the context of the 2025 Personal Data Protection Law (“PDP Law”) and Decree 13 imposing stricter requirements on data processing activities, reviewing international case studies is essential for businesses to identify risks and strengthen their compliance frameworks. Incidents involving British Airways, the Academy of Medicine Singapore, Shein, and TikTok demonstrate that even a single gap in security measures, internal procedures, or consent-management mechanisms can result in large-scale data breaches and significant regulatory penalties. This article consolidates and analyses these cases in comparison with the corresponding provisions of the PDPL and Decree 13, with the aim of providing Vietnamese businesses with practical lessons to improve their technical safeguards, privacy policies, and data-governance processes.
Cross-border data transfer and processing is increasingly common in the context of intense digitalization. In order to ensure data security and comply with legal regulations, Decree 165/2025/ND-CP has issued an impact assessment procedure before data is transferred abroad.
The breach of the General Data Protection Regulations (GDPR) at the H&M Service Center in Nuremberg, Germany is an important legal "case study" on the privacy of workers at enterprises. Perhaps this will be an issue that causes controversy and even frequent disputes in the near future in Vietnam, when the Law on Personal Data Protection 2025 will take effect from January 1, 2026.
The protection of children's personal data has become a global concern amid the rapid development of the Internet and social platforms. In the EU, the General Data Protection Regulation (GDPR) has special provisions aimed at protecting children online. Similarly, the U.S. applies the COPPA Child Privacy Protection Act.
The legal framework governing the operation of Data Centers (DC) in Vietnam is built on the basis of basic laws on technology and telecommunications. Initially, the general rules on information technology application and development activities were established in the Law on Information Technology 2006. This law provides general principles, including the right to apply information technology in commerce and regulations on specialized inspections. In parallel, the Telecommunications Law 2023 sets out a framework for the management of telecommunications networks and services, including encouraging infrastructure development.
Businesses that use personal data to serve the goal of promoting products and services may face many obstacles in the near future. They can be sued for ad spam and it is difficult to avoid legal litigation.
Individual customer image data is becoming a valuable resource for businesses. From the use of surveillance cameras in retail stores, facial recognition in payment systems, to image analysis for marketing purposes, businesses are leveraging this type of data to enhance customer experience and optimize business operations. However, in the context that Vietnam is requiring strict protection of personal data, the way businesses collect and process customer image data will have many changes.
For many businesses, in the coming time, marketing activities must be reviewed and shaped new strategies to comply with the new legal framework on personal data protection that Vietnam has issued in 2025. Many new, complex and far-reaching requirements will place many responsibilities on the shoulders of businesses that are not very easy.