The publication "Legal Guidelines: Compliance with Personal Data Protection Law in Vietnam for Businesses" was compiled by HM&P Law Firm ("HM&P") to accompany the business community in the process of approaching, correctly understanding and effectively applying current legal regulations. With comprehensive, practical and up-to-date content, the publication not only analyzes the domestic legal framework but also puts it in relation to international experiences from Europe, the United States, and Singapore – regions that have built a developed data protection legal system early on.
Targeted advertising campaigns have become the main tool of businesses in reaching consumers today. From searching for a car, buying a book, or simply stopping for a few seconds in front of a video on social media, the hidden data system then silently records, analyzes, and "personalizes" the next ad that appears on your screen. That's the power of data, but it's also the source of new legal risks, security risks, and personal privacy risks.
Cyberspace has become an integral part of children's lives. From online learning and social media entertainment, to gaming and accessing digital health services, children are generating and sharing vast amounts of personal data. However, children often lack awareness of the risks associated with collecting, using, and sharing this data, leading to problems such as misuse of information, targeted advertising, or even cybersecurity threats. Therefore, the protection of children's personal data in cyberspace has become a top priority in international legal frameworks.
In today's era of strong digitalization, personal data has become a valuable asset but also full of risks for organizations and businesses. With the rise of data breaches and stricter legal regulations, protecting personal information is no longer an option but a mandatory obligation. One of the most important tools for achieving this compliance is Data Mapping – also known as data mapping. Data Mapping not only helps organizations understand their "data panorama" but also serves as a foundation for the implementation of legal requirements for personal data protection globally, especially those from regulatory agencies.
Technology and digitalization are rapidly changing professional professions and legal fields that are not out of that spiral. Artificial Intelligence (AI) has become a powerful tool, helping lawyers and legal professionals improve their work efficiency, from document research to contract analysis. However, this convenience comes with challenges in terms of professional ethics, information security, and liability.
Multinational corporations (MNCs), especially micro-MNCs in Southeast Asia (ASEAN), are increasingly relying on the transfer of personal data between internal offices to support centralized business functions such as finance, human resources, etc research and development (R&D), or customer service. However, cross-border transfers of personal data are subject to strict data protection regulations in the countries concerned, which can vary significantly. This article will analyze the essential elements that multinational enterprises should include in the Group Internal Agreement when transferring personal data between offices in multiple countries, and clarify the role of this agreement in the context of ASEAN.
In the era of rapidly developing artificial intelligence (AI) technology, the use of data to train AI models has become a core factor for creating competitive products. However, unauthorized use of copyrighted data can lead to serious legal disputes, causing financial and reputational losses. Thomson Reuters Enterprise Centre GmbH v. West Publishing Corp. v. Ross Intelligence Inc. (2025) in the District Court of Delaware, USA is a good example, clearly illustrating the risks of copyright infringement during AI development.
On July 1, 2025, the Prime Minister issued Decision 20/2025/QD-TTg, officially announcing the list of important data and core data of Vietnam. This is an important step in the context that Vietnam is promoting digital transformation, building e-Government and protecting cyber security according to the Data Law 2024. The list clearly distinguishes which types of data are considered critical and which are considered core data with different protection requirements. With 26 types of core data and 43 types of important data, this Decision reflects the State's priority in protecting national interests, security and socio-economic development.
In the era of digital transformation and international integration, cross-border data transfer, including personal data, is becoming increasingly essential, playing an important role in the economy, trade and management. Vietnam has developed two important legal documents to regulate this activity: the Data Law 2024 passed by the National Assembly on November 30, 2024, effective from July 1, 2025) and the Law on Personal Data Protection 2025 adopted on June 26, 2025, which will take effect from January 1, 2026. While both laws are intended to govern and protect data, their scope and focus differ. If the Data Law 2024 regulates all digital data, treating data as a national asset, while the Personal Data Protection Law 2025 focuses on protecting personal privacy.
Vietnam is promoting national digital transformation and deep integration into the global economy, cyberspace has become an important driving force for economic and social development, but at the same time, it also poses many challenges in cybersecurity. The Draft Law on Cyber Security 2025, developed to consolidate the Law on Cyber Information Security 2015 and the Law on Cyber Security 2018 (the "Draft"), not only aims to protect national sovereignty in cyberspace but also create significant changes in the business environment, especially for businesses operating in the fields of information technology, network services, and cybersecurity. This article will analyze the impacts of the draft law on business operations, from simplifying administrative procedures, improving the business environment, to new challenges that businesses need to face.
According to the provisions of Decree 69/2024/ND-CP, accounts issued by the National Public Service Portal and the information system for handling administrative procedures at ministerial and provincial levels to agencies and organizations can only be used until the end of June 30, 2025. Although businesses can still continue to carry out administrative procedures with these accounts, switching to using VNeID level 2 electronic identification accounts is necessary, not only to meet the regulations on deadlines, but also to gradually change the mindset of approaching public services in the direction of digitalization. synchronize and authenticate user identities.
On 7 July 2025, at the Personal Data Protection Week 2025 held in Singapore, the Minister of Digital Development and Information, Ms. Josephine Teo, delivered an inspiring opening speech, emphasizing the importance of data protection, especially personal data in the context of a rapidly changing world. With the theme "Data Protection in a Changing World" , her speech addressed the challenges and opportunities that the development of technology, especially artificial intelligence (AI), brings in the field of data governance. This article will delve into the key takeaways from her speech and examine how Singapore is shaping a secure and reliable digital future.