Legal Guidelines: Compliance with Personal Data Protection Law in Vietnam for Businesses

Insights
Legal Guidelines: Compliance with Personal Data Protection Law in Vietnam for Businesses
Posted on: 17/10/2025

    FOREWORD

    In the age of digitalization and global connectivity, personal data has become one of the most important assets – not only for individuals, but also for organizations, businesses, and countries. However, the protection of personal data in Vietnam for a long time is still scattered, lacking in systematization and has not been regulated by a specialized legal document.

    Before 2023, the right to privacy was mainly mentioned scattered in the Constitution and a number of specialized laws, with inconsistent interpretation and application. The introduction of the Government's Decree 13/2023/ND-CP dated April 17, 2023 on personal data protection ("Decree 13") marks an important turning point, establishing a comprehensive legal framework on personal data protection in Vietnam for the first time. Following this foundation, the Law on Personal Data Protection No. 91/2025/QH15 was approved by  the 15th National Assembly on June 26, 2025 and takes effect from January 1, 2026 (the "Law on Personal Data Protection "),  further strengthening Vietnam's commitment to integrate with international standards, and at the same time, improve responsibility and standardize data processing behavior in all areas of life.

    The publication "Legal Guidelines: Compliance with Personal Data Protection Law in Vietnam for Businesses" was  compiled by HM&P Law Firm ("HM&P") to accompany the business community in the process of approaching, correctly understanding and effectively applying current legal regulations. With comprehensive, practical and up-to-date content, the publication not only analyzes the domestic legal framework but also puts it in relation to international experiences from Europe, the United States, and Singapore – regions that have built a developed data protection legal system early on.

    Within the scope of this publication, the Law on Personal Data Protection (“PDP”), Decree 13 and the draft decree detailing a number of articles of the Law on PDP – the consultation dated 12/9/2025 ("Draft Decree guiding the Law on PDP")  before being adopted will be used as a basis for analysis, interpretation and providing practical guidance for enterprises in the process of developing and implementing the chapter compliance submissions.

    At the same time, the content of the publication is built based on HM&P's multi-disciplinary and multi-disciplinary legal practices, from start-ups, manufacturing enterprises, technology companies to multinational corporations, in which the security of information and personal data is always the top priority in legal advice and solutions. We hope that this publication will be a useful reference for businesses, investors, organizations and individuals operating in Vietnam – pioneering businesses that are gradually building a culture of compliance, towards sustainable and responsible development in the data era in Vietnam.

    If you have any questions about the contents of this document, please contact HM&P using the information below:

    Our Managing Partner:

    Lawyer Nguyen Van Phuc

    Phone: 0932 768 630

    Email: phuc.nguyen@hmplaw.vn

    HM&P Law Firm

    Address: 7th Floor, ITAXA House, 126 Nguyen Thi Minh Khai, Xuan Hoa Ward, HCMC

    Phone: +84 28 73080839

    Email: counsel@hmplaw.vn

    Website: hmplaw.vn

    Note:

    This publication is intended to provide general information only and is not a substitute for legal advice on a case-by-case basis. Therefore, readers should consult a lawyer or legal expert before applying. Any questions regarding content or intellectual property rights should be directed to: counsel@hmplaw.vn                                      

    HM&P Law Firm is a professional law firm with experience in providing multi-disciplinary legal advice, including PDP. To learn more about the legal services we provide in this field, please contact us by email:  phuc.nguyen@hmplaw.vn

     

    PART I. SUMMARY OF LEGAL REGULATIONS ON PDP IN VIETNAM

    1. Definitions

    1.1. Personal data

    According to the Law on PDP, personal data is digital data or other form of information that identifies or helps to identify a specific person, including basic personal data and sensitive personal data. In which:

    Basic personal data

    Sensitive personal data

    It is a personal data that reflects common personal and background factors, often used in transactions and social relations, on the list issued by the Government.

    As a personal data associated with the privacy of individuals, when infringed, it will directly affect the legitimate rights and interests of agencies, organizations and individuals, on the list issued by the Government.

    Currently, there are no detailed guidelines on the categories of basic and sensitive personal data. However, enterprises can refer to the provisions of Decree 13 and the Draft Decree guiding the Law on PDP. Accordingly:

     

    Decree 13

    Draft Decree guiding the Law on PDP

    (additional provisions compared to Decree 13 are in italics)

    Basic personal data

    • Full name; birthday; gender;
    • Birthplace; nationality;
    • Personal image;
    • Phone number;
    • Number of legal documents;
    • Marital status; family information;
    • Account information and activity history;
    • Other information helps identify a specific person (not in a sensitive group).

    Basic personal data is personal data that reflects common personal and background factors, often used in transactions and social relationships, and is not on the list of sensitive personal data.

    Sensitive personal data

    • Political and religious views;
    • Health status (excluding blood type);
    • Ethnic origin;
    • Genetic information, biological characteristics;
    • Banking and credit data;
    • Defined location data;
    • Information on land associated with individuals;
    • Salary and other income information.
    • Data revealing racial and ethnic origins;
    • Views on politics, religion and belief;
    • Data disclosures about private life;
    • Health status;
    • Biometric data, genetic characteristics;
    • Data revealing the sex life and sexual orientation of individuals;
    • Data on crimes and criminal acts collected and stored by law enforcement agencies;
    • The individual's location is determined through location services;
    • Electronic identity of individuals;
    • Username and password of the account; bank card information, data on transaction history of bank accounts; financial and credit information and other information related to financial, securities and insurance transactions of customers at credit institutions, foreign bank branches, payment intermediary service providers, securities, insurance, and other licensed organizations;
    • Data on activities and operation history of telecommunications subscribers;
    • Data to track behaviors and activities of using telecommunications services, social networks, online communication services and other services in cyberspace;
    • Other personal data that is required by law to be kept confidential or determined by organizations and individuals needs to take strict security measures.

    In addition, the Law on PDP also adds a stipulation that personal data after de-identification is no longer a personal data. In particular, personal data de-identification is the process of changing or deleting information to create new data that cannot be identified or cannot help identify a specific person, and must ensure the principle of not re-identifying personal data after it has been de-identified[1].

    Currently, the Law on PDP has not provided specific regulations on the method of data de-identification. Businesses can refer to international standards such as the guidelines of the Singapore PDP Commission. Accordingly, a de-identification process is only considered satisfactory when certain criteria are fully met: personal traceability, very low risk of re-identification, appropriate technical and administrative measures, consistently applied and verifiable by documentation,  evaluation report:[2]

    Example:

    Company A wants to analyze the shopping behavior of customers to serve the optimization of business strategies. Company A owns a file of customer data that has shopped at its website, including: full name, gender, year of birth, email, phone number, address and purchase history.

    To ensure compliance with regulations on PDP, A signs a contract with Company B – a provider of data analysis solutions. Before sending data to B, A conducts de-identification by:

    • Remove information directly related to the customer's identity, such as username, email address, and shipping address.
    • Replace the information with a random ordinal number, making sure it has no connection to customer information.
    • Only  non-personally identifiable information such as year of birth, gender, order history, shopping frequency, and product type is retained for the purpose of analyzing shopping behavior.
    • At the same time, security measures are applied, ensuring that data is not leaked or re-identified.

    In this case, the data that A provides to B is not considered personal data, because it has been de-identified before transfer.

     

     

    1.2. Related entities in the process of processing personal data

    1.2.1. Data subjects:

    The data subject is the individual to whom the data is reflected,[3] who owns all rights to his or her information. Therefore, all collection and processing activities must respect and protect this right to the fullest. In an enterprise, a data subject can be a customer, partner, employee, or any individual with whom the business collects and processes data.

    1.2.2. Personal data controllers, personal data processors, personal data controllers and processors, and third parties

     

    1.2.3. Defining the roles of parties to personal data

    Illustrative examples

    Situation:

    Company A operates in the service sector, with 200 employees. Every year, A organizes periodic health checks for employees, and at the same time carries out procedures for social insurance and personnel record keeping. Specifically:

    1. Company A sends the list and information of employees to Hospital B to arrange periodic health check-ups.
    2. Hospital B receives information, contacts staff to inform the examination schedule and conduct the examination at the request of Company A.
    3. After the examination, Hospital B sends the results to Company A.
    4. Company A uses the results of the examination to update the employee's records and send relevant information to the Social Insurance agency of Ward X to fulfill the obligation to report, compensate or other regimes for employees.
    5. Personnel records, including personal information and work history, are stored on the system of Company C – a cloud storage service provider. Company C only stores data and does not process it for its own purposes.

    Role

    Definition

    Organizations/individuals

    Explain

    Personal Data Controller

    It is the organization or individual who decides what data is collected, for what purpose, and by what means.

    Company A

    Decide on the type of data to be collected (employee information), purpose (medical examination, record management, implementation of Social Insurance) and means of processing (renting Hospital B, using C's storage service).

    Personal Data Processor

    It is an organization or individual that performs activities such as collection, analysis, encryption, deletion, etc. in accordance with the direction and contract with the controller, the data may not be used for other purposes.

    Hospital B, Social Insurance Agency of Ward X

    Collect, process or use data according to the direction and purpose of Company A, not use the data for its own purposes.

    Third Party

    An organization or individual that is not a data subject, controller or data processor, but participates in one or more personal data processing activities arising outside the direct contractual relationship between the controller and the processor.

    Company C

    Not being the controller or the direct processor under the medical examination contract, but participating in the storage of data, arising out of the processing contract between Company A and Hospital B.

    Recommendations:

    Before the issuance of Decree 13, many contracts or agreements related to personal data processing activities did not clearly stipulate which party has the right to decide the purpose or means of data processing, leading to difficulties in determining the roles and responsibilities of the parties when an incident occurs. To overcome this, enterprises should negotiate, adjust or supplement the content of contracts/agreements, specify rights and obligations, clearly identify the party deciding the purpose, means, form of handling, as well as responsibilities when there is an incident. Enterprises especially need to consider supplementing or updating the terms on personal data handling in contracts/agreements with partners and suppliers, in order to serve reporting requirements according to the State's regulations and clearly ensure the responsibilities of each party, thereby complying with the law and minimizing legal risks.

    1.3. Personal data processing

    According to the Law on PDP, personal data processing activities include:

    Recommendations:

    Enterprises should note that according to the Law on PDP, all activities related to personal data listed above are considered "data processing". Therefore, enterprises should review the entire operation process, clearly identify each type of processing activity being carried out, thereby establishing appropriate security measures, a mechanism for obtaining transparent consent and records to ensure compliance with the law as well as limit legal risks.

    1.4. Responsibility for appointing departments/personnel or hiring a PDP service provider of the enterprise

    The Law on PDP requires enterprises to appoint departments and personnel who are qualified to protect personal data or hire organizations and individuals to provide PDP services.[4] This obligation applies to all enterprises, except for cases exempted under Clauses 2 and 3, Article 38 of the Law.

    Specifically, the Law allows the following enterprises and organizations (except for enterprises and organizations providing personal data processing services, directly handling sensitive personal data or handling a large number of personal data subjects) to choose whether or not to appoint  a department,  personnel or hire an organization to provide PDP services[5]:

    Groups of businesses/organizations

    Exemption criteria

    Startups

    Currently, there is no general definition of a startup. However, we will use the closest definition of "innovative startup". Accordingly, an innovative start-up is an enterprise established to implement an idea on the basis of exploiting intellectual property, technology, new business models and has the ability to grow rapidly. 

    → To  choose whether or not to appoint/hire PDP services for 05 years from the effective date of the Law on PDP.

    Small business[6]

    Agriculture, forestry, fisheries; industry and construction: Enterprises with an average annual number of employees participating in social insurance from 11 to not more than 100 people, and at the same time have a total annual revenue of more than 3 billion VND to not more than 50 billion VND or a total capital of more than 3 billion VND to not more than 20 billion VND.

    Trade and service sector: Enterprises with an average annual number of employees participating in social insurance from 11 to not more than 50 people, and at the same time have a total annual revenue of more than 10 billion VND to not more than 100 billion VND or a total capital of more than 3 billion VND to not more than 50 billion VND.

    → To choose whether or not to appoint/hire PDP services for 05 years from the effective date of the Law on PDP.

    Microenterprises[7]

    Agriculture, forestry, fisheries; industry and construction: Enterprises with an average annual number of employees participating in social insurance are not more than 10 people and the total revenue of the year does not exceed 3 billion VND or the total capital of the year does not exceed 3 billion VND.

    Trade and service sector: Enterprises with an average annual number of employees participating in social insurance are not more than 10 people and the total revenue of the year is not more than 10 billion VND or the total capital of the year does not exceed 3 billion VND.

    It is not mandatory to  assign/hire a PDP service.[8]

    Business households

    Household business is a type of business registered by an individual or household members in accordance with the provisions of law and is responsible with all their assets for the business activities of the business household.[9]It is not mandatory to  assign/hire a PDP service.[10]

     

    The Draft Decree guiding the Law on PDP supplements regulations on the time of termination of the application of the exemption mechanism for enterprises and organizations. Specifically:

    • For small organizations and start-ups: the exemption no longer applies from the time the scale of personal data processing reaches 100,000 personal data subjects or more.
    • For business households and micro-organizations: exemption no longer applies from the time the scale of personal data processing reaches 500,000 personal data subjects or more.

    Recommendations:

    Enterprises need to review the scale and nature of personal data processing to determine the obligation to appoint personnel/departments or hire PDP services, as well as consider the possibility of being exempted. Even if a temporary exemption is granted, businesses should proactively plan to arrange personnel in charge or outsource PDP services to build compliance capacity soon. For small businesses or start-ups, hiring external PDP services is a cost-effective solution but still meets legal requirements.

    2. Issues to note during the collection and processing of personal data

    2.1. Data subject consent requirements

    The data subject is only considered to have given a valid consent when it simultaneously meets the following 05 conditions:[11]

    1. Voluntary, knowing and unconditional: Before making a decision, the subject has been fully informed of the type of data to be collected, the purpose of use, the controller/processor and his or her rights and obligations. Consent must not be associated with a requirement to accept purposes other than the agreed content.[12]
    2. Clear & Specific: Consent must be expressed by a clear affirmative action (such as checking the "consent" box, signing, electronic confirmation, audio/video recording, etc.), not defaulting to silence or non-response,  expressed through formal and content requirements  as described below.[13]
    3. Verifiability: Archival records (paper or electronic) must be printable, with signatures, seals, digital signatures, or recordings/calls for later verification.[14]
    4. Corresponding purposes: If there are multiple purposes of processing, each purpose must be listed separately so that the subject can agree in part, not forced to accept them all.[15]
    5. Sensitive data: For sensitive data (health, biometrics, etc.), the subject must be specifically informed that this is "sensitive data" before collection.[16]

     2.2. Obligation to notify when processing personal data

    According to the provisions of the Law on PDP, prior notification of each personal data processing[17] (as previously stipulated in Decree 13) will no longer be required; however, the personal data controller and the personal data processor must still perform the obligation to notify the personal data subject in certain cases.

    Cases in which the personal data controller and the personal data processor need to perform the obligation to notify the personal data subject

    STT

    Case

    Illustrative examples

    1

    When the controller or the data controller and processor is unable to delete or destroy personal data at the legitimate request of the data subject, it must promptly notify the data subject and take measures to protect his/her interests.[18]

    Situation at commercial banks:

    An individual customer submits a request to delete the entire personal data after the settlement and bank account has been closed. However, the bank was unable to implement this request immediately due to the legal requirement to store transaction records and identification data for 5–10 years to serve the goal of anti-money laundering and internal audits.[19]

    Responsibility to Notify: The Bank is obliged to clearly inform the reason why the data cannot be deleted, the relevant legal basis (such as the Anti-Money Laundering Law), the remaining retention period and the applicable data protection measures (encryption, access restrictions, etc  etc.) so that the subject understands his rights and protects himself.

    2

    In financial and banking activities or the provision of credit information, if there is any disclosure, loss or leakage of personal data related to bank accounts, credit information, etc., the data controller and processor must immediately notify the data subject so that the subject can proactively respond.[20]

    Situation at the e-wallet service provider:
    A technical problem caused the database of the e-wallet system to be accessed without authorization, leading to the leakage of personal information (full name, phone number, transaction history, account balance) of more than 1,000 users.

    Responsibility for Notification: The organization must immediately send a notification to the affected data subjects, describing in detail the type of data breached, when it occurred, the extent of the impact, and proposing countermeasures such as: temporary locking of wallets, changing passwords, contact the support hotline, and recommend monitoring fraudulent transactions.

    3

    For social networking platforms and online services, businesses must clearly notify all types of personal data to be collected when the data subject installs, registers or uses the platform and absolutely does not collect data outside the scope notified and agreed with the subject.[21]

    Situation at the food delivery app:
     When the user installs the app, the system silently accesses the device's GPS location, contacts, and search history without explicitly stating it in the privacy policy, nor does it require partial consent.

    Responsibility for notification: Enterprises must update their data collection policies in the direction of transparency, fully list the types of collected data (location, contacts, devices, etc.), clearly state the corresponding purpose of processing for each type, and allow users to have the option of "partial consent". Unnotified collection is a violation and should be corrected before further processing of the data.

    4

    For biometric data, enterprises note that only when the processing of biometric data (such as fingerprints, faces) leads to actual damage to the data subject, the organization/individual collecting and processing must notify the data subject in accordance with the Government's regulations.[22]

    Situations at the fitness center when using the facial recognition app:

    A gym uses a facial recognition camera system to allow members to enter/exit. Due to a security flaw, a third party gained access to the biometric data of multiple members and used that image to impersonate the system, causing the loss of assets.

    Responsibility for notification: The Center must proactively notify each affected member specifically, clearly stating the type of exposed data (biometric data - face), the consequences that have occurred, and remedial plans such as: disabling old data, switching to multi-factor authentication (MFA), and provide legal or financial assistance if there is damage.

    5

    When applying measures of surveillance (audio and video recording) and processing of personal data obtained from audio and video recording activities in public places or public activities, agencies, organizations and individuals do not need to ask for consent, but must notify or apply equivalent forms of information so that the data subject knows that they are being recorded (unless permitted by law without notification) in the following cases[23]:

     ·  Performing the tasks of national defense, security and social order or protecting the legitimate rights and interests of agencies, organizations and individuals;

    · Public  activities (conferences, seminars, sports, art performances, etc.) without harming the honor, dignity and reputation of individuals;

    ·  Other cases prescribed by law.

     

    Situation at the factory:

    The enterprise installs CCTV systems in the production workshop areas, corridors and entrance gates to serve the purpose of ensuring safety, security and internal control. In the process of operation, there are two groups of subjects under supervision:

    Responsibility for Notification:

    • Visitors (without a contractual relationship with the enterprise): Visitors to the factory or enterprise do not need to ask for consent to  the audio and video recording for the purpose of security and supervision of the factory, but  the enterprise must publicly announce (through boards, signs, instructions) that the area has cameras/video recordings,  and data is only used for the right purpose, stored for the necessary period. However, businesses should note that if businesses want to use visitors' images for other purposes (e.g., advertising, communication), they must ask for their own consent before using them.
    • Employees (with labor contracts with enterprises): CCTV surveillance is considered as data processing activities to perform labor contracts, serving the goals of labor safety, monitoring the production process and internal security. Therefore, enterprises can process personal data without asking for separate consent from the subject, as long as the use of data is for the right purpose and does not exceed the scope agreed in the labor contract. However, businesses still need to publicly announce with boards/signs in areas where surveillance cameras are installed to ensure transparency.

    In addition to the cases that must be notified under the Law on PDP, the Draft Decree guiding the Law on PDP also expands a number of situations in which enterprises must actively notify the subject of personal data, including:

    • When the controller or the data controller and processor needs to extend the processing time for a request to withdraw consent, request to view, correct, provide, and/or delete the data, it must notify the data subject of the reason for the extension[24].
    • When the data subject's personal data is used in the big data analysis system, relevant agencies, organizations and individuals must have an appropriate mechanism for notifying and explaining to the data subject[25].
    • In the artificial intelligence system and virtual universe, the party that controls and processes personal data must notify the data subject of the automatic processing of the personal data, explain the influence of algorithms, artificial intelligence and automated systems on the legitimate rights and interests of the data subject[26].
    • In cloud computing, organizations and individuals who sign contracts related to the processing of personal data with organizations providing cloud computing services must immediately notify the relevant parties of any changes that may affect the personal data.
    • Enterprises should closely monitor the Draft Decree and promptly update it when the Decree is officially promulgated, to ensure full compliance with legal obligations on PDP.

     

    General Secretary To Lam and Prime Minister Pham Minh Chinh congratulated the Standing Committee of the National Data Association for the 2025-2030 term. Source: Government Newspaper

    Please read more and download full content of publication (PDF File) here


    [1] Article 2.11, Article 14.6 of the Law on PDP

    [2] Singapore PDP Commission (2013), c, amended, supplemented on 23/5/2024

    [3] Article 5.2 Law on PDP

    [4] Article 33.2 of the Law on PDP

    [5] Article 38.2 Law on PDP

    [6] Article 5.2 of Decree 80/2021/ND-CP

    [7] Article 5.1 of Decree 80/2021/ND-CP

    [8] Article 38.2 Law on PDP

    [9] Article 3.2 of Resolution 198/2025/QH15

    [10] Article 38.2 Law on PDP

    [11] Article 9 of the Law on PDP

    [12] Articles 9.2 and 9.4. (b) Law on PDP

    [13] Article 9.3 of the Law on PDP, Article 6 of the Draft Decree guiding the Law on PDP

    [14] Article 9.3 of the Law on PDP

    [15] Article 9.4. (a) Law on PDP

    [16] Article 31.3. (b), Article 31.4. (b), Article 32.2, Article 29.1 of the Law on PDP

    [17] Clause 1, Article 13 of Decree 13

    [18] Article 14.5 of the Law on PDP

    [19] Article 38 of the Law on Prevention and Combat of Money Laundering

    [20] Article 27.1. (d) Law on PDP

    [21] Article 29.1 of the Law on PDP

    [22] Article 31.4. (b) Law on PDP

    [23] Article 32.2 of the Law on PDP

    [24] Article 5 of the Draft Decree guiding the Law on PDP

    [25] Article 9.2 (m) Draft Decree guiding the Law on PDP

    [26] Article 10.4 Draft Decree guiding the Law on PDP