The article provides some in-depth opinions on legal risks and expected litigation trends related to personal data privacy in Vietnam in the near future. Especially from January 1, 2026, the time when the Law on Personal Data Protection (Law on PDP) officially takes effect and creates a solid foundation for litigation activities to protect the privacy.

1. The transition from Decree 13/2023/ND-CP to the Law on PDP
The personal data protection legal environment in Vietnam is undergoing an important transition, starting with Decree 13/2023/ND-CP (Decree 13) and continuing with the PDP Law which will come into effect in 2026. Decree 13, effective from July 1, 2023, is the third legal document issued in the plan to strengthen the legal framework regulating activities in cyberspace, after the Law on Cyber Security and Decree 53/2022/ND-CP.
The Law on PDP is considered the most important legal framework with the goal of regulating all fields, overcoming the remaining limitations of Decree 13. The official promulgation of the Law on PDP will transform data compliance from a strategic choice to a mandatory obligation, in order to ensure that all data processing activities are implemented safely and transparently, while improving the competitiveness of businesses in the digital transformation journey.
The complex data governance obligations established under Decree 13, which have been strengthened in the Law on PDP, include the preparation and maintenance of Data Protection Impact Assessment (DPIA) and Overseas Transfer Impact Assessment (OTIA) reports. In particular, for cross-border data transfers, enterprises must complete and submit an OTIA report within 60 days of the start of processing or transfer. Any changes in the content of the OTIA dossier must be notified to the Department of Cyber Security and High-tech Crime Prevention and Combat, Ministry of Public Security, within 10 working days. The transition from Decree 13 to the Law on PDP has created a significant compliance "gap" for organizations. Businesses often find it difficult to complete and maintain the up-to-date of complex DPIA/OTIA records. Omissions or sketchy in these administrative documents pose great risks. In the event of a cybersecurity breach or data leak, especially after the data has been transferred across borders, incomplete DPIA/OTIA records can be evidence to prove the irresponsibility or mismanagement of the business.
The Law on PDP has established a strict financial penalty threshold for violations of the law on personal data protection. The maximum fine level for other violations in this field is VND 03 billion or 5% of turnover for organizations. For individuals committing the same violation, the maximum fine level is equal to half of the fine level for organizations. In addition, the law also prohibits the sale of personal data, and prohibits the theft and sale of personal data in cyberspace.
The significant penalties underscore Vietnam’s strong commitment to protecting its citizens’ personal data. This high penalty threshold has a strategic effect on civil lawsuits. Although civil lawsuits in Vietnam require plaintiffs to prove actual damages, lawyers representing plaintiffs will argue that this maximum administrative penalty is a basis for assessing the severity of the violation. This argument has the potential to drive up the cost of out-of-court settlements and increase the pressure on the moral damage liability that the Courts may impose.
2. Privacy disputes that are likely to occur in Vietnam in 2026
2.1. User data leakage disputes
The largest class action civil litigation in Vietnam from 2026 is expected to revolve around data breaches. The recent major data leak incidents in Vietnam by Vietnam Airline or the Vietnam National Credit Information Center (CIC) are a high wake-up call for data leaks in Vietnam in the near future.
The legal basis for these lawsuits will focus on alleging the business failed to "implement and maintain reasonable security processes and practices," based on its security deficiencies. Examples of shortcomings that are commonly cited include: lack of adequate email filtering software, failure to train employees, failure to implement multi-factor authentication (MFA), lack of data encryption, or retention of personal data unnecessarily or beyond the required time.
2.2. Disputes over online marketing activities
The Law on PDP grants data subjects 11 fundamental rights, including the right to know, consent, access, and the right to request data deletion,.... Compliance disputes will arise when the enterprise fails to comply with the requirements to exercise this right within the stipulated time limit.
In particular, the dispute over the withdrawal of consent will be a "hot spot" in the near future. When an individual withdraws their consent to data processing, the business must stop processing the data. If the business continues to use the data for marketing purposes or to share it with third parties after receiving a withdrawal request, this will be a clear and easily proven basis for litigation.
In addition, intrusive marketing behaviors, such as spam messages and harassment calls, are currently being handled by citizens through a reporting mechanism to the authorities. However, once the Law on PDP has come into effect, with the legal environment strengthened, individuals who have been subjected to unauthorized data use are likely to seek to collectiveize these cases and initiate civil lawsuits. With the argument that continuous harassment such as misuse of personal data violates privacy and causes time damage and mental damage. At this time, it is possible that personal issues will be scaled up into large-scale and complex lawsuits with many parties involved.
2.3. Disputes in cross-border data management
The regulation on the transfer of personal data abroad is a strict compliance requirement in Decree 13 and the future PDP Law. Any business that transfers data abroad must complete an OTIA and notify the Department of Cyber Security.
The omission or failure to update the OTIA record may be grounds for administrative sanctions and civil litigation, especially if the data transfer results in data leakage or loss. Moreover, with the increase in cross-border transactions and stricter legal scrutiny in the Asia-Pacific region, B2B disputes have increased. Vietnamese companies that process data for foreign partners (outsourced) will face the risk of being litigated by their partners if they violate data protection commitments in the agreed contract between the parties. In addition, the transfer of internal data of multinational companies out of Vietnam's borders also poses many potential dispute risks, especially in the field of labor.

Source: The Saigon Times
3. Risks from specialized disputes
3.1. Finance – technology industry
Fintech businesses face the highest legal risks due to the processing of large volumes of sensitive financial data. Violating security regulations can lead to large fines and litigation from customers or stakeholders Securing and complying with cybersecurity regulations is paramount to the sustainable success of businesses in this sector.
To deal with this challenge, the implementation of advanced technological security measures is a prerequisite to minimize the risk of litigation. This includes building a strict access decentralization system based on the principle of "least privilege," applying multi-factor authentication (MFA), data encryption, firewalls, and intrusion detection/prevention systems (IDS/IPS).
3.2. Sensitive data of the health sector
The health sector in Vietnam has many intrinsic weaknesses, including the fact that many facilities still use paper records, lack of system connectivity or synchronization, and vulnerable medical mobile applications (mHealth) due to a lack of security development standards.
The biggest danger comes from ransomware attacks[2] that target the healthcare system, crippling the system and losing, exposing and leaking patient data. This attack is very likely to occur in Vietnam when the public health system is centralized, strengthening the ability to deploy synchronously on a large scale with many vulnerabilities during this transition period.
While the development of a national data interconnection standard in health makes information retrieval efficient, it creates a high-risk focal point. If this point of connection is hacked, the scale of the damage will be enormous, triggering large-scale civil lawsuits based on the severity of the disclosure of Sensitive Personal Data, similar to lawsuits over biometric data.
3.3. Disputes over derivative shareholders
Although the Shareholder Derivative Actions in Vietnam has not developed as strongly as in other countries, especially in the US. Big data leaks of shareholders that cause serious damage and cause a decrease in the market value of the business will create an incentive for shareholders to conduct class action lawsuits to claim compensation when an incident occurs.
In the U.S. model, shareholders sued the company's management for failing to fulfill its duty of care by failing to protect the company from cybersecurity threats[3]. These lawsuits held management accountable, leading to corporate governance reforms, increased cybersecurity budgets, and changes in senior personnel. In Vietnam, this risk will motivate shareholders to seek governance accountability, forcing leaders to implement governance and cybersecurity reforms to protect the company's assets and reputation.
4. What do businesses need to prepare to minimize risks?
4.1. Enhancing transparency in the process of collecting personal data
Businesses must transition from a model of implicit consent to a clear, voluntary, specific and transparent opt-in mechanism for data processing activities, especially sharing with third parties (for marketing) and the collection of sensitive data.[4]
The management of digital tracking tools is paramount. Businesses need to understand the purpose of using third-party data. If the vendor has the ability to use the data for his or her own purposes (acting as a traditional eavesdropper), businesses need to ensure that there is specific consent for that sharing. The application of cookies and privacy policies should be clear, accessible, and provide a mechanism for users to opt out of data collection to avoid potential lawsuits.
4.2. Mechanism for responding to data subjects quickly and effectively
The Law on PDP sets clear requirements for compliance with the rights of data subjects. Businesses must establish a prompt and efficient response process to meet these rights. For example, in the event of an incident, the security team needs to be able to trace and reproduce the entire sequence of events in a short time to complete the impact report and notify the data subject in time.
Transparency in the handling of data deletion or deletion requests is key to compliance. When a data subject requests the exercise of rights, enterprises need to provide information or take action in a complete and timely manner, avoiding compliance disputes, which are the clear legal basis for litigation disputes in this field.
4.3. Build a clear system of legal evidence for defense
High-quality compliance records are the first line of legal defense. Impact assessment records (DPIA/OTIA) must be maintained and updated regularly. These documents are the most important evidence to prove that the company has adopted "reasonable security practices" in court if a leak occurs.
Any contracts with data processors must clearly provide for confidentiality responsibilities, limitations on the purposes of the processing, and must include explicit indemnification clauses if the processor causes a breach. This is to transfer legal responsibility away from the business.
Finally, the application of clear, fair, and accessible Limitation of Liability Clauses in the terms of service is an essential legal defense tool against breach of contract lawsuits when a data incident occurs.
The transition from Decree 13 to the Law on PDP marks a turning point and at the same time creates a favorable legal environment for civil disputes claiming compensation for damages that may occur frequently in the near future. As a result, the likelihood that companies operating in Vietnam will face complex types of litigation is becoming more and more apparent in the field of protecting the privacy of individuals in Vietnam. Careful, reasonable and effective preparation will help businesses avoid unnecessary losses in the future not only in terms of material but also reputational.
[1] An article in HM&P’s “Wednesday for Data” series.
[2] Ransomware is malware that encrypts your files or prevents you from using your computer until you pay (ransom) for them to be unlocked. See more at: https://support.microsoft.com/vi-vn/windows/b%E1%BA%A3o-v%E1%BB%87-pc-c%E1%BB%A7a-b%E1%BA%A1n-ch%E1%BB%91ng-l%E1%BA%A1i-m%C3%A3-%C4%91%E1%BB%99c-t%E1%BB%91ng-ti%E1%BB%81n-08ed68a7-939f-726c-7e84-a72ba92c01c3, last accessed on 02/12/2025.
[3] https://tuoitre.vn/co-dong-khoi-kien-facebook-vi-lo-thong-tin-nguoi-dung-20180321143152468.htm, last accessed on 02/12/2025.
[4] Opt-In is a voluntary/active user action to receive new information from your business via email. Users will subscribe to a list on a specific website, company, or individual, from which you have the right to send emails to subscribers.
