Vietnam's PDPL Explained: Inside the Country's Primary Privacy Legislation
Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15) took effect on 1 January 2026, replacing Decree 13 as the country's primary privacy framework. This guide covers consent rules, DPIA and cross-border transfer dossiers, 72-hour data subject rights timelines, the data trading ban, and fines of up to 5% of annual revenue.

What is Vietnam's PDPL?
Vietnam's Law on Personal Data Protection (PDPL) — Law No. 91/2025/QH15 — is the country's first comprehensive privacy statute. Passed by the National Assembly on 26 June 2025 and effective from 1 January 2026, it elevates personal data protection from decree level to full legislation, replacing Decree 13/2023/ND-CP (the PDPD) as the primary legal framework governing how personal data of Vietnamese citizens is collected, processed, stored, shared, and transferred.
The PDPL matters because Vietnam is one of Southeast Asia's largest digital economies, with roughly 80 million internet users and one of the region's highest social media penetration rates. Until 2023, data protection obligations were scattered across the Cybersecurity Law, the Law on Network Information Security, and sector rules. The PDPL consolidates them into a single enforceable regime — with revenue-based fines that put it firmly in GDPR territory.
From Decree 13 to Law: What Changed
Decree 13/2023 introduced Vietnam's core privacy concepts — consent, sensitive data, impact assessments, cross-border dossiers — but as a decree it sat below statute in the legal hierarchy and its penalty regime was limited. The PDPL keeps the decree's architecture largely intact while hardening it: obligations are now statutory, penalties are dramatically higher, and several new processing contexts are regulated explicitly.
The law adds targeted rules for areas the decree never addressed: employee monitoring and recruitment data, health and insurance data, financial and credit information, biometric data, location data, personal data in advertising, and — notably — processing in the context of artificial intelligence, blockchain, the metaverse, and cloud computing. Organisations that built their programmes on Decree 13 have a head start, but 'Decree 13 compliant' is not the same as 'PDPL compliant'.
Scope: Who Must Comply
The PDPL applies to Vietnamese agencies, organisations, and individuals; foreign organisations and individuals in Vietnam; and — critically — foreign entities located outside Vietnam that are directly involved in or related to processing personal data of Vietnamese citizens and people of Vietnamese origin residing in Vietnam. Like GDPR, it reaches offshore SaaS companies, e-commerce platforms, and advertising networks that serve Vietnamese users without any local presence.
The law retains the controller/processor structure familiar from GDPR and Decree 13: 'data controllers' decide purposes and means, 'data processors' process on a controller's behalf, and combined 'controller-processors' do both. Obligations attach to each role, so mapping which of your entities plays which role for each processing activity is a foundational compliance step.
Consent Remains the Centre of Gravity
Vietnam's regime is consent-centric — more so than GDPR, which offers six lawful bases. Under the PDPL, consent must be freely given, informed, explicit, and demonstrable, given for specific purposes, and expressed through an affirmative act. Silence and pre-ticked boxes do not constitute consent, and consent for one purpose cannot be bundled with another. Data subjects may give partial or conditional consent and may withdraw it at any time.
There are exceptions — emergencies threatening life or health, national security, legal obligations, and certain contractual and publicly disclosed data scenarios — but they are narrower than GDPR's legitimate-interest basis. Practically, this means most commercial processing of Vietnamese users' data needs a working consent infrastructure: purpose-specific capture, timestamped records, easy withdrawal, and the ability to prove consent on demand, since the burden of proof sits with the controller.
Sensitive Data and High-Risk Processing Contexts
The PDPL distinguishes 'basic' from 'sensitive' personal data. Sensitive data includes political and religious views, health and medical records, genetic and biometric data, sex life and sexual orientation, criminal records, financial and credit information, location data, and other data prescribed by law. Processing sensitive data triggers heightened obligations, including notifying the data subject that sensitive data is being processed and applying stronger safeguards.
The law also imposes context-specific rules: recruitment data must be handled with consent and deleted when hiring purposes end; employee monitoring must be disclosed; health and insurance data cannot be shared with insurers for underwriting without explicit consent; and organisations deploying AI systems that process personal data must manage the associated risks and inform users. If you operate chatbots, recommendation engines, or model training pipelines that touch Vietnamese user data, those systems are now squarely in scope.
Impact Assessments and Cross-Border Transfer Dossiers
Vietnam's most distinctive compliance mechanism carries over from Decree 13: mandatory dossiers filed with the Ministry of Public Security (A05). Controllers and processors must prepare a Data Processing Impact Assessment (DPIA) dossier within 60 days of commencing processing, and any transfer of Vietnamese citizens' personal data abroad requires an Outbound Transfer Impact Assessment (OTIA) dossier — kept available for inspection and submitted to the authority.
Unlike GDPR adequacy decisions or SCCs, this is a notification-and-inspection regime: you do not wait for approval, but the regulator can review, demand changes, and order suspension of transfers. The PDPL streamlines some of the decree-era paperwork and provides exemptions for certain small businesses and startups, but the core obligation stands. Multinationals moving Vietnamese HR or customer data to regional data centres, global CRMs, or US-based cloud analytics need these dossiers in place and kept current as systems change — which is exactly where an automatically maintained data map pays for itself.
Data Subject Rights
The PDPL grants Vietnamese data subjects a broad rights catalogue: the right to be informed about processing; to give, refuse, and withdraw consent; to access, view, correct, and request correction of their data; to delete or request deletion; to restrict processing; to obtain a copy of their data; to object to processing; to complain, denounce, and initiate lawsuits; to claim compensation for damage; and to self-protect through legally recognised measures.
Response timelines are tight by international standards — restriction and objection requests, for example, must generally be actioned within 72 hours. Meeting that window with a manual, inbox-driven DSR process is unrealistic at any scale; organisations serving Vietnamese users should automate intake, identity verification, fulfilment across connected systems, and audit-trail generation.
The Data Trading Ban and Penalties
The PDPL flatly prohibits the buying and selling of personal data in all forms, closing a loophole that fuelled Vietnam's grey market in leaked databases. Violations of the trading ban can attract fines of up to ten times the revenue gained from the violation. For unlawful cross-border transfers, administrative fines can reach 5% of the violating organisation's revenue of the preceding fiscal year — a ceiling that exceeds GDPR's 4% benchmark. Other violations carry fines up to VND 3 billion, with criminal liability possible in serious cases.
Enforcement sits with the Ministry of Public Security, which has been notably active on data protection — including high-profile actions over data leaks and unlawful data trading. Vietnamese enforcement should be planned for as a real operational risk, not a theoretical one.
Organisational Requirements and Grace Periods
Organisations must designate personnel or a department responsible for personal data protection, and controllers processing sensitive data must appoint personnel with data protection expertise — a role analogous to the GDPR DPO. A domestic professional services market is also anticipated: the law contemplates data protection credentials, ratings, and certified DPO services.
There is meaningful relief for smaller players: micro, small, and medium-sized enterprises and startups may be exempt from the DPO-appointment and dossier obligations for their first five years of establishment (with opt-outs and exclusions — data processing businesses and sensitive-data-heavy firms don't qualify). If you're a foreign SaaS company, however, don't count on these exemptions; assess your obligations as a controller of Vietnamese users' data on the full timeline.
A Practical PDPL Compliance Roadmap
Start with discovery and mapping: identify every system that touches Vietnamese citizens' personal data, classify what's basic versus sensitive, and document where it flows — especially across borders, since each outbound flow needs an OTIA dossier. This inventory drives everything else: your DPIA dossiers, consent scopes, and retention rules.
Then operationalise: deploy purpose-specific consent capture with verifiable records and easy withdrawal; stand up a DSR workflow capable of 72-hour turnarounds; prepare and file DPIA and OTIA dossiers with A05; appoint your data protection personnel; and review AI, advertising, and employee-data processing against the PDPL's context-specific rules. Organisations already aligned to GDPR or India's DPDP Act will recognise the shape of the work — but Vietnam's dossier regime, consent-first model, and 72-hour timelines are stricter in places, and they deserve their own workstream rather than a copy-paste of an existing programme.
Related articles
Introducing the TruePrivacy Endpoint Agent: PII Discovery for Employee Laptops
India DPDPA Compliance Guide: Requirements, Rights, Consent, and Governance
AI Privacy Impact Assessment: A Step-by-Step Template for EU AI Act Compliance
Automate your privacy compliance
See how TruePrivacy can handle DSRs, consent, and breach response — all in one platform.
Free 14-day trial · No credit card required · Setup in minutes