๐Ÿ‡ป๐Ÿ‡ณVietnam

PDPL

Law on Personal Data Protection (Law No. 91/2025/QH15)

Vietnam's first comprehensive privacy statute, replacing Decree 13/2023 as the primary framework for processing Vietnamese citizens' personal data, with revenue-based fines and mandatory regulator dossiers.

Overview

Vietnam's Law on Personal Data Protection (PDPL) โ€” Law No. 91/2025/QH15 โ€” is the country's first comprehensive privacy statute. Passed by the National Assembly on June 26, 2025 and effective from January 1, 2026, it elevates personal data protection from decree level to full legislation, replacing Decree 13/2023/ND-CP (PDPD) as the primary framework governing the collection, processing, storage, sharing, and cross-border transfer of Vietnamese citizens' personal data.

The PDPL retains the consent-centric architecture introduced by Decree 13 while significantly hardening the regime: revenue-based fines of up to 5% of prior-year revenue for unlawful cross-border transfers, a flat prohibition on buying and selling personal data with fines up to ten times the illicit gain, and new context-specific rules for recruitment data, employee monitoring, health and insurance data, financial and credit information, biometric and location data, advertising, and processing involving artificial intelligence, blockchain, and cloud computing.

Enforcement sits with the Ministry of Public Security (Department A05), which has been notably active on data protection โ€” including high-profile actions against data leaks and unlawful data trading. Combined with mandatory impact-assessment dossiers filed with the regulator, Vietnam operates one of the most administratively demanding privacy regimes in Southeast Asia.

Scope & Applicability

The PDPL applies to Vietnamese agencies, organisations, and individuals; foreign organisations and individuals operating in Vietnam; and foreign entities located outside Vietnam that are directly involved in or related to processing the personal data of Vietnamese citizens and people of Vietnamese origin residing in Vietnam. Like GDPR, it reaches offshore SaaS companies, e-commerce platforms, and advertising networks serving Vietnamese users without a local presence. The law distinguishes data controllers, data processors, and combined controller-processors, with obligations attaching to each role, and classifies personal data as 'basic' or 'sensitive' โ€” the latter including health, biometric, genetic, financial and credit, location, and criminal-record data.

Key Principles

  1. 1
    Consent-centric processing โ€” explicit, informed, affirmative consent for each specific purpose, with narrow exceptions (emergencies, national security, legal obligations)
  2. 2
    Purpose limitation โ€” personal data may only be processed for the purposes consented to; bundled consent across purposes is not valid
  3. 3
    Data minimisation and proportionality โ€” collection must be limited to what is necessary for the declared purpose
  4. 4
    Transparency โ€” data subjects must be informed of processing, and notified specifically when sensitive data is processed
  5. 5
    Security of processing โ€” appropriate technical and organisational measures, with breach reporting to the Ministry of Public Security
  6. 6
    Accountability through dossiers โ€” Data Processing Impact Assessment (DPIA) and Outbound Transfer Impact Assessment (OTIA) dossiers must be prepared and filed with authority A05
  7. 7
    Prohibition on data trading โ€” buying and selling personal data is banned in all forms
  8. 8
    Storage limitation โ€” personal data must be deleted when the purpose is fulfilled or consent is withdrawn

Data Subject Rights

Right to Know and Be Informed

Data subjects must be informed about the processing of their personal data before or at the time of collection, including purposes, data types, and the organisations involved.

Right to Consent, Refuse, and Withdraw Consent

Consent must be given by affirmative act for each specific purpose and can be partial or conditional. Data subjects may withdraw consent at any time, after which processing must stop.

Right to Access and Correction

Data subjects can view, access, and request correction of their personal data, or correct it themselves where the controller provides the means.

Right to Deletion

Data subjects can delete or request deletion of their personal data, including when consent is withdrawn or the processing purpose has been fulfilled.

Right to Restrict Processing and Object

Data subjects can request restriction of processing or object to processing; controllers must generally action such requests within 72 hours.

Right to Obtain a Copy of Data

Data subjects can request a copy of their personal data from the controller.

Right to Complain, Sue, and Claim Compensation

Data subjects can complain, denounce violations, initiate lawsuits, and claim compensation for damage caused by violations of their personal data rights.

Business Obligations

Maintain a Valid Consent Infrastructure

Capture purpose-specific, timestamped, demonstrable consent with easy withdrawal. The burden of proving valid consent lies with the controller โ€” silence and pre-ticked boxes do not qualify.

Prepare and File DPIA Dossiers

Controllers and processors must prepare a Data Processing Impact Assessment dossier within 60 days of commencing processing and keep it available for inspection by the Ministry of Public Security (A05).

Prepare OTIA Dossiers for Cross-Border Transfers

Any transfer of Vietnamese citizens' personal data abroad requires an Outbound Transfer Impact Assessment dossier filed with A05, kept current as systems and flows change.

Designate Data Protection Personnel

Organisations must designate personnel or a department responsible for personal data protection; controllers of sensitive data must appoint personnel with data protection expertise (a DPO-equivalent role). Qualifying SMEs and startups may be exempt for their first five years.

Do Not Buy or Sell Personal Data

The PDPL flatly prohibits trading personal data in all forms, with fines of up to ten times the revenue gained from the violation.

Manage High-Risk Processing Contexts

Context-specific rules govern recruitment data, employee monitoring, health and insurance data, financial and credit information, advertising, and AI systems that process personal data โ€” including obligations to disclose and manage AI-related risks.

Report Data Breaches

Personal data breaches and violations must be notified to the Ministry of Public Security (A05) within 72 hours, with supporting documentation of the incident and remediation.

Cross-Border Transfer Rules

Vietnam operates a dossier-based (notification-and-inspection) transfer regime rather than adequacy decisions or standard contractual clauses. Transferring Vietnamese citizens' personal data abroad โ€” including storing it on foreign cloud infrastructure โ€” requires an Outbound Transfer Impact Assessment (OTIA) dossier prepared before the transfer and submitted to the Ministry of Public Security (A05). Transfers do not require prior approval, but the regulator can inspect dossiers, demand changes, and order suspension of transfers where violations occur or national security is affected. Unlawful cross-border transfers can attract administrative fines of up to 5% of the organisation's revenue of the preceding fiscal year. The PDPL provides limited exemptions for certain small enterprises and startups.

Breach Notification Requirements

Notification Timeline

72 hours from the occurrence of a violation or breach involving personal data

Notify Authority

Ministry of Public Security โ€” Department of Cybersecurity and Hi-Tech Crime Prevention (A05)

Notify Individuals

Data subjects must be informed of incidents affecting their personal data; controllers should document the breach, its impact, and remediation measures

How TruePrivacy Helps

Purpose-built tools for every PDPL obligation.

PDPL-Compliant Consent Management

Purpose-specific consent capture with affirmative-act UX, timestamped and versioned records, partial consent support, and one-click withdrawal โ€” producing the evidence trail the PDPL demands from controllers.

DPIA and OTIA Dossier Automation

Generate and maintain Data Processing Impact Assessment and Outbound Transfer Impact Assessment documentation from your live data map, so A05 dossiers stay current as systems and vendors change.

72-Hour DSR Automation

Automated intake, identity verification, and fulfilment across connected systems keep restriction, objection, and deletion requests within the PDPL's 72-hour response window.

Cross-Border Transfer Mapping

Automatically discover every flow of Vietnamese users' data to foreign systems and cloud regions, flagging transfers that need an OTIA dossier before they happen.

Breach Notification Workflows

Pre-built incident playbooks and notification templates help you assess, document, and report breaches to A05 within the 72-hour deadline.

AI and Sensitive Data Governance

Inventory AI systems and sensitive data processing, apply the PDPL's heightened safeguards, and document risk management for AI-driven processing of Vietnamese personal data.

Ready to achieve PDPL compliance?

TruePrivacy automates your compliance workflows so your team can focus on what matters.

Free 14-day trial ยท No credit card required ยท Setup in minutes