E-commerce and digital transformation playing an increasingly important role in business activities, domain names are no longer just an access address on the Internet, but have become valuable commercial assets, associated with the brand, reputation and presence of businesses in the digital environment. However, along with this increasing role is the risk of arising legal disputes related to domain names – a type of dispute that is developing more and more complex and diverse in practice.
On June 26, 2025, the National Assembly of Vietnam passed the Law on Personal Data Protection 2025 (PDPL 2025), which will take effect from January 1, 2026, marking an important step forward in perfecting the legal framework for personal data protection in Vietnam. Along with Decree 13/2023/ND-CP (PDPD 2023), which came into effect on July 1, 2023, these regulations set new and stricter requirements for businesses to process personal data. In the context of strong digital transformation, personal data has become a valuable asset but also a target of abuse, from information leakage to unauthorized trading. So what do businesses need to do to comply with new legal requirements, mitigate risks and maintain a competitive advantage? This article will analyze the necessary preparation steps, from reviewing internal processes to implementing technical, legal, and administrative measures.
On June 26, 2025, at the 9th session, the 15th National Assembly of Vietnam officially approved the Law on Personal Data Protection (the PDPL), marking an important milestone in building a legal framework for personal data protection in the context of strong digital transformation. The PDPL with 39 articles, effective from January 1, 2026, is divided into 5 chapters, not only meeting the internal needs for the protection of citizens' rights but also in line with international trends in personal data management.
In the context of global digital transformation, personal data has become an important resource, especially in the labor sector, where personal information of employees and candidates is regularly collected, processed, and stored. In Vietnam, the Draft Law on Personal Data Protection (Draft), especially Article 21 , is designed to establish a legal framework for personal data protection in the recruitment and management of workers. This regulation reflects Vietnam's efforts to integrate with international standards, such as the European Union's General Data Protection Regulation (GDPR), and meet the requirements for privacy protection in the context of Vietnam.
Global digital transformation is taking place at a rapid pace, cloud services such as Microsoft 365 have become indispensable tools for public organizations as well as private organizations. However, the use of these platforms poses a major challenge in terms of personal data protection, especially when data is transferred outside the domestic jurisdiction. The case of the European Commission (EC) being investigated and sanctioned by the European Data Protection Authority (EDPS) for using Microsoft 365 is a wake-up call for the protection of personal data in the public sector of many countries. The EDPS decision not only sheds light on the gaps in data management of one of the most powerful bodies in the European Union (EU), but also provides important lessons for countries like Vietnam, where the legal framework for protecting personal data is being built.
The answer is not simple and depends on the legislative philosophy, the level of technological development, and the cultural perspective on privacy in each country. Some countries, especially in Europe, consider personal data as a fundamental human right and apply strict regulations. Meanwhile, in other regions, such as the United States, the approach is somewhat more flexible, creating a legal gray area where personal data is still widely traded. In this article, we will analyze the legal frameworks in key regions of the world – Europe, North America, Asia, Oceania, and South America – to clarify how countries handle the purchase and sale of personal data, while assessing global trends and making recommendations for Vietnam.
Digital transformation is advancing rapidly in Vietnam, protecting personal data has become a top priority in many countries, including Vietnam. Decree 13/2023/ND-CP on Personal Data Protection has laid the foundation for the legal framework for data protection, and the Draft Law on Personal Data Protection (the "Draft"), which was submitted to the National Assembly at its 9th session (May 2025) and is expected to be adopted at this session, is expected to complete one of Vietnam's most important laws in personal data protection. With 68 provisions ranging from general regulations to the responsibilities of stakeholders, the Draft represents an effort to build a comprehensive legal framework. However, some contents in the draft are still unclear, difficult to implement, or not in line with the economic, social and legal practices of Vietnam.
In the rapid digital technological advancement, personal data has become a valuable resource but also has many potential risks. The protection of personal data is not only a legal requirement but also a vital factor to maintain user trust and ensure national security. The Draft Law on Personal Data Protection of Vietnam (the "Draft"), is expected to be approved by the National Assembly in 2025 and take effect on January 1, 2026. One of the key highlights of the draft is the regulation on personal data protection experts – a new but decisive role in the enforcement of data protection laws. In this article, we will analyze in detail the content related to DPO according to the latest Draft being submitted to the National Assembly at the 9th session, May 2025.
Personal data is becoming the target of increasingly sophisticated cyberattacks. The hacker attack on VNDirect Securities Joint Stock Company in March 2024 is a warning bell about vulnerabilities in personal data protection in Vietnam. This incident not only disrupts business activities but also exposes the limitations of the current legal framework, and sets an urgent requirement to build a more comprehensive and effective legal system for personal data protection. This article will analyze the VNDirect case, thereby proposing solutions to build and improve personal data protection laws in Vietnam.
The rapid development of technology and the cyber environment has made the protection of personal data (PD) an urgent requirement in Vietnam. The draft Law on Personal Data Protection (the "Draft") has been drafted by the Ministry of Public Security to be submitted to the National Assembly for comments and may be approved as soon as this year. The Law on Protection of Personal Data is expected to create a comprehensive legal framework to protect the privacy of individuals, while meeting international standards to which Vietnam is a member. However, some opinions say that this draft is setting too many administrative procedures, creating a burden on businesses, especially small and medium enterprises (SMEs) as well as start-ups, and going against the goals of administrative reform as well as promoting the digital economy set by the Government.
In the context of rapid digital technology development, personal data has become a valuable asset not only for individuals and organizations but also for the economy. However, data security faces many challenges due to the increasing activities of data collection and usage without stringent control. To address this issue, the Draft of Law on Protection of Personal Data (“Proposition”) has been released for public consultation with the intention of being enacted and taking effect from January 1st 2026 , as planned by the National Assembly. The regulations elevating personal data protection to the status of law are considered a significant step forward in safeguarding personal information and promoting the development of the digital economy. However, the Draft still contains some limitations that need to be carefully assessed and adjusted to better align with practical realities.
In the digital age, securities companies and investment funds must handle vast amounts of personal data, including sensitive information such as bank account numbers and transaction history. Decree No. 13/2023/ND-CP on personal data protection ("Decree 13") imposes strict rules on data collection, analysis, and sharing to protect users' rights.