In the context of rapid digital technology development, personal data has become a valuable asset not only for individuals and organizations but also for the economy. However, data security faces many challenges due to the increasing activities of data collection and usage without stringent control. To address this issue, the Draft of Law on Protection of Personal Data (“Proposition”) has been released for public consultation with the intention of being enacted and taking effect from January 1st 2026[1], as planned by the National Assembly. The regulations elevating personal data protection to the status of law are considered a significant step forward in safeguarding personal information and promoting the development of the digital economy. However, the Draft still contains some limitations that need to be carefully assessed and adjusted to better align with practical realities.
.jpg)
Some provisions should be more carefully considered
Consent of the data owner
Before processing personal data, businesses must notify the data subject and obtain their consent, which is a prerequisite for carrying out such activities. Consent is only valid if it is given voluntarily and when the data subject is fully aware of the types of data, the purpose of processing, the organization conducting the processing, as well as their rights and obligations. Furthermore, consent must be expressed through a clear action, such as a written statement, voice, checking a consent box, or through consent syntax in messages, and it must be capable of being printed or copied in a verifiable format[2].
The provision regarding the consent of the data subject is a crucial element in enhancing individual control and promoting responsible data collection mechanisms. However, the requirement to obtain consent from the data subject before carrying out any processing activity could create significant obstacles. This not only increases the workload but also affects the flexibility of businesses. Although Article 17 of the Draft has introduced some exceptions to this consent requirement, these exceptions are still much narrower than those in international data protection laws. Businesses and data subjects in Vietnam may have to repeatedly request and provide consent, even if the activities align with the original purpose of processing.
Timeframe for responding to data subject requests
Currently, the Draft requires the Data Controller and Processor to provide, rectify, and delete personal data within 72 hours after receiving a request from the data subject[3]. This time-frame may pose significant challenges for businesses, as they need time to verify the identity of the requester, clarify the request, assess the results and impact of the adjustment, notify the data subject, and ensure the data subject understands the consequences of their request. Therefore, it is necessary to consider adjusting the time period within which businesses must respond to data subject requests.
Data protection responsibilities of the Data Controller and Processor
Article 47 of the Draft stipulates that businesses must implement management and technical measures to protect the data of the data subjects. For basic personal data such as full name, nationality, citizen identification number, or marital status, protective measures include appointing a personal data protection organization, personal data protection experts, and requiring a cybersecurity audit for the systems and devices used for data processing. For sensitive personal data such as political views, religious beliefs, health status, sexual orientation, or location data, businesses must conduct a trust assessment on personal data protection as per Article 41 of the Proposition.
This provision reflects efforts to control and enhance the responsibilities of organizations and individuals involved in personal data control and processing. However, it also imposes a cost burden due to the requirement to implement high-level security measures, which requires businesses to invest in security technologies and specialized personnel. Especially for small and medium-sized enterprises, they may face significant costs to maintain modern security systems. Moreover, the regulation does not clearly delineate the responsibilities of the parties involved. For instance, in the event of a data security breach, does the responsibility lie with the organization or individual tasked with protecting the data, or with the business using the information In the event of a data security breach, does the responsibility lie with the organization or individual tasked with protecting the data, or with the business using the information ?
Personal data protection trust rating
A new feature in the Draft is the regulation on personal data protection trust ratings. Organizations certified by the relevant authorities will assess the credibility of organizations or individuals involved in personal data processing. The evaluation will consider factors such as macro risks, market conditions, technology, strategy, governance, personnel, and finances[4]. This scope of evaluation requires highly specialized expertise.
While this regulation aims to ensure that businesses are qualified to process personal data, practical implementation is likely to be challenging. Article 41 requires trust analysts to have one to two years of experience in information security or legal fields. However, given the broad scope of the evaluation, it is essential to combine expertise from other areas such as economics, finance, and labor. At the same time, the criteria and evaluation methods in the Draft remain vague and unclear, requiring appropriate adjustments.

Some suggested adjustments
The establishment of a legal framework to protect personal data in the context of increasingly important information is essential. However, the Draft still contains some limitations that need to be adjusted to balance individual rights and the capacity of businesses. Based on the process of reviewing the provisions of the Proposition, as well as the implementation of the regulations in Decree No. 13/2023/ND-CP on personal data protection, the author suggests the following adjustments to the Proposition:
First, the regulation on the consent of the data subject should be more flexible: Article 11 could include exceptions to the consent requirement, such as in cases where legal obligations must be fulfilled, for the legitimate interests of the data subject, to prevent fraud, or for arising benefits like updating products or services.
Second, the time-frame for responding to requests should be extended: The current 72-hour period may be too short. The Draft could consider provisions from the EU General Data Protection Regulation (GDPR) or Singapore's Personal Data Protection Act (PDPA), which allow a response time of up to 30 days to ensure sufficient time for processing requests.
Third, the responsibilities of the parties involved should be clearly assigned: It is necessary to clarify the responsibilities of each party involved in data protection, including service providers and businesses using the data. The government could also support small and medium-sized enterprises in complying with these regulations.
Fourth, adjust the provisions on personal data protection trust ratings: The criteria and methods for assessing trust levels need to be adjusted to ensure feasibility and effectiveness in implementation. In addition, cooperation from experts in various fields is necessary, as requiring only one to two years of experience in cybersecurity or legal matters is not sufficient to carry out a comprehensive assessment based on the scope of the evaluation.
Overall, the Draft represents an important step in protecting individual rights in the digital age, establishing a legal foundation for transparent and secure personal data processing. However, to ensure feasibility and consistency, and to build a safe and sustainable legal environment for personal data, certain key provisions must be adjusted and clarified to balance the interests of citizens and businesses.
[1] https://thuvienphapluat.vn/van-ban/Bo-may-hanh-chinh/Luat-Bao-ve-du-lieu-ca-nhan-625628.aspx, last accessed dated December 16th 2024.
[2] Article 11 of the Proposition
[3] Articles 13, 14, 15, 16 of the Proposition
[4] Article 41 of the Proposition
