Unlike passwords or bank card numbers that can be changed, biometric data is permanently tied to the human body. Once illegally collected, used, or leaked, individuals have almost no ability to "recall" or "reset" their biological characteristics. Therefore, many legal systems around the world have considered biometric data as sensitive personal data and set strict protection requirements.

Biometric data as sensitive personal data and set strict protection requirements
The time of easy and indifferent biometric data collection, considered normal in the processing and storage of user biometric data of businesses in Vietnam is now forced to end. In Vietnam, the new legal framework promulgated and effective from January 1, 2026 on personal data protection, including the Law on Personal Data Protection 2025 (the Law on PDP) and the Government's Decree 356/2025/ND-CP detailing and implementing measures for the Law on PDP, has officially included biometric data[1] in the group of sensitive data that needs to be protected at a high level the most.
Businesses must change
When biometric data – including facial recognition, fingerprints, iris, voice – has been classified as sensitive data, businesses and organizations are forced to implement a series of technical and legal measures to comply and ensure the safety of this data. In addition to the basic obligations that organizations that collect and process personal data must comply with such as ensuring the rights of personal data subjects, implementing appropriate management and technical measures to protect personal data. The Law on PDP requires agencies, organizations and individuals that collect and process biometric data to perform the following other obligations:
Internal management requirements. When processing this type of data, agencies and organizations must establish regulations on decentralization, limit access rights, develop processing processes and apply specialized security measures. When transferring biometric data, the organization is required to apply encryption, anonymization, or de-identification measures before transferring it outside or to another entity.
Request a problem report. In the event of a biometric data leakage or loss, the organization is responsible for notifying the PDP Agency of the Ministry of Public Security within 72 hours from the date of discovery. At the same time, the organization must also notify the data subject of the violation affecting their biometric data, except in case of urgent technical difficulties, which may be publicly announced later.
Requirements for small and medium-sized businesses. Although small, micro and startup businesses have the option not to implement some regulations on human resources and data protection technology in the first 05 years, this right does not apply if they directly process biometric data.
In fact, lawsuits due to the breach of users' biometric data around the world are not uncommon. The class action lawsuit Patel v. Facebook, Inc., arising from Facebook's implementation of the "Tag Suggestions" feature since 2010, is a good example of this type of dispute due to a data breach. To operate the tagging suggestion feature, Facebook automatically scans user photos, extracts facial geometric features (the distance between the eyes, nose, ears, etc.) and creates a "face pattern" to match the available database[2].
The legal dispute arose when Facebook collected and stored users' biometric data in the state of Illinois without notice and written consent, in violation of the Illinois Biometric Information Privacy Act (BIPA) of 2008. BIPA requires businesses to publicize their biometric data storage and destruction policies, collect biometric data only when the purpose and time limit are clearly notified and the written consent of the user, and at the same time allow individuals to file lawsuits directly and claim predetermined compensation from 1,000 to 5,000 US dollars per violation. offense.
The lawsuit reached an agreement in Court, Facebook was forced to accept mediation at a price of 650 million US dollars, and at the same time had to make a series of commitments to the regulator such as switching to an "opt-in" mechanism - only collecting when users consent, removing unauthorized facial patterns, etc implement the enhancement of transparency in the processing of biometric data.
There may be similar "Patel v. Facebook" in Vietnam?
Previously, Facebook also implemented facial recognition in the Vietnamese market. But fortunately at that time, the issue of protecting personal data, especially biometric data in Vietnam, was not given proper attention. However, at this time, the legal framework is clear, the awareness of the privacy rights of Vietnamese people is different from before, so if a similar violation occurs now, the legal consequences may have been reversed.

Source: The Saigon Times
With a series of violations similar to Facebook, such as not clearly notifying about the collection of biometric data such as not having a clear consent mechanism, storing facial samples for a long time, not giving users control over data, at this time, businesses can violate a series of obligations under the Law on PDP such as (i) Violating the obligation to agreed; (ii) Violating the principle of transparency; (iii) Violating the principle of limiting the storage time. These are completely serious violations under Vietnamese law and businesses may be subject to the highest sanctions.
Unlike the US, Vietnam does not have a mechanism for initiating a class action lawsuit and has not stipulated a predetermined level of compensation for each violation. However, the Law on PDP still opens up many legal avenues for the infringed party. Accordingly, infringed individuals can complain and denounce to the management agency or choose to initiate a civil lawsuit to request the termination of the violation; apologize and make public corrections; or compensation for both material and mental damages. In addition, if the unauthorized data processing causes serious consequences, the enterprise may be subject to criminal liability under the Criminal Code.
Although the compensation mechanism in Vietnam is not as "strong" as the laws of developed countries, the trend of strengthening privacy protection shows that legal risks for businesses will be increasing.
To make business operations safer
Biometric data is directly related to identity, body, and personal safety. The processing of this data is not only a technological and legal issue, but also a human rights issue. Therefore, businesses must have a change in legal and governance thinking towards biometric data.
Businesses cannot continue to rely on "collection default" mechanisms and then allow users to "turn it off". Consent must be proactive, clear and provable. Businesses must consider ensuring the security of this data as the highest priority by applying a series of measures from building an internal data governance framework, strengthening technical security to cooperating with specialized legal units, techniques to develop a backup plan and respond to this data leak are very necessary in the current context. As the rapid development of the era of artificial intelligence and big data, biometric data is becoming "digital gold". But accompanying the economic value is a huge legal risk.
Biometric data is being considered as the only "universal key" of each individual. These are characteristics that cannot be changed like changing passwords, so the law requires that the key be stored in the most secure safe (encrypted), guarded by a professional guard (DPO personnel) and any signs of intrusion must be immediately reported to the police within the shortest time (72 hours). Any violation of this type of data is considered a violation at the highest level and is dealt with in the most severe way. This is not only how the world treats this type of data, but even Vietnam will apply if any violation occurs.
Lawyer Nguyen Van Phuc
HM&P Law Firm
Read more: Đừng đùa với dữ liệu sinh trắc học người dùng
[1] Clause 2, Article 31 of the Law on PDP
