VIETER
VIETNAM INDUSTRY BRIEFING

Vietnam’s new Personal Data Protection Law: What businesses must know before 2026

Vietnam’s digital transformation has accelerated rapidly in recent years, and with it, the need for robust data protection has become more urgent than ever. On 26 June 2025, the National Assembly passed the Personal Data Protection Law (PDPL)—a landmark r

Vietnam’s digital transformation has accelerated rapidly in recent years, and with it, the need for robust data protection has become more urgent than ever. On 26 June 2025, the National Assembly passed the Personal Data Protection Law (PDPL)—a landmark regulation that will take effect on 1 January 2026. This law replaces Decree 13 and introduces a more comprehensive, enforceable framework for how personal data must be handled across sectors.

The purpose of this article is to provide businesses—whether newly established, unfamiliar with personal data protection regulations, or already compliant under Decree 13—with a clear and practical understanding of the PDPL. We aim to help you identify what’s new, what’s expected, and how to prepare effectively.

Understanding personal data under the PDPL, key definitions

The PDPL retains the core definition of personal data as any information that can identify an individual. However, it expands the scope to include both digital and non-digital formats, meaning even paper-based records now fall under the law’s protection.

The law distinguishes between basic personal data—information commonly used in transactions and social interactions that reflects identity and background—and sensitive personal data, which, by nature, poses a direct risk to the legitimate rights and interests of individuals, organizations, or authorities if compromised. The Government is authorized to define and detail the specific categories of both basic and sensitive data.

Although guidance under the new legal definition is still pending, Decree 13 currently identifies sensitive personal data to include political and religious views, health status, criminal history, and biometric data. Processing sensitive data requires heightened safeguards and stricter legal justification. This shift signals Vietnam’s alignment with global data protection norms, where sensitivity and context matter as much as volume.

Personal DataAny information that identifies or can be used to identify an individual—now explicitly includes both digital and paper-based formats.

 

Basic Personal DataThis refers to data that reflects common aspects of personal identity and background, frequently used in transactions and social interactions. Detailed guidance from the Government is still pending.

Examples: Name, gender, residential address, personal photographs, etc.

Sensitive Personal DataThis type of data is closely tied to an individual’s privacy. If compromised, it can directly impact the legitimate rights and interests of individuals, organizations, or authorities. Government guidance on specific categories is still awaited.

Processing sensitive data requires stricter safeguards and legal justification.

Examples: Political opinions, religious beliefs, health status, criminal history, biometric data, etc.

Personal Data ProcessingRefers to any activity that affects personal data, including one or more of the following: collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, anonymization, provision, disclosure, transfer, and other actions involving personal data.
Data SubjectThe individual to whom the personal data relates.

Examples: Employees, individual customers.

Data ControllerEntity that determines the purpose and means of processing personal data.

Examples: Employers, companies.

Data ProcessorEntity that processes data on behalf of the controller.

Examples: Vendors, suppliers, partners.

Data Controller-cum-ProcessorAn entity that both determines the purposes and means of processing and directly processes personal data.

Examples: Employers, companies.

Third PartyAn external entity authorized to process personal data but not acting as a controller or processor. Identification of such entities may vary depending on specific circumstances and requires further discussion.

Typically, entities that control or process personal data (excluding the data subject) must comply with a series of procedures and requirements. These include establishing internal policies, completing data protection impact assessments, and adhering to data protection commitments throughout the entire lifecycle of data processing—from obtaining consent, conducting the processing, to terminating the processing activities in accordance with legal regulations.

What businesses are required to do

The PDPL introduces a more structured compliance regime, requiring businesses to demonstrate not only lawful data collection but also responsible and transparent processing. The law outlines six core categories of obligations, each addressing a different aspect of data governance. In addition, businesses must prepare and submit two types of reports to the Ministry of Public Security (MPS), depending on their activities.

ObligationsDetailsDeadline / Trigger
Obtain Explicit ConsentConsent must be clear, informed, and freely given. Exceptions apply only in legally defined cases (e.g., public interest, legal obligations).Before processing personal data
Conduct Data Protection Impact Assessments ReportsThis requirement applies to entities that control or process personal data, unless otherwise specified by law. The obligation is typically fulfilled once, within the legally prescribed timeframe, but must be updated if there are changes to the data processing activities. It includes the submission of:

1. Personal Data Processing Impact Assessment (DPIAs)

2. Cross-Border Personal Data Transfer Impact Assessment

· Personal Data Processing Impact Assessment: Within 60 days of starting data processing activities.

· Cross-Border Personal Data Transfer Impact Assessment: within 60 days of initiating the transfer or processing using systems located abroad.

Appoint a Data Protection Officer (DPO)Mandatory for medium and large enterprises, and any business engaged in high-risk data processing, such as handling sensitive personal data or conducting cross-border transfers.

The DPO ensures internal compliance and serves as a liaison with regulators.

Has not yet been officially defined
Implement Security MeasuresBusinesses must adopt technical and organizational safeguards to prevent unauthorized access, breaches, or misuse.Ongoing – must be in place before and during data processing
Ensure Lawful Cross-Border TransfersTransfers must meet strict conditions, including DPIAs and legal justifications. Consent alone may not suffice.Required before transferring personal data outside Vietnam
Notify Authorities of ViolationsData breaches must be reported promptly, with clear documentation and mitigation steps. The PDPL emphasizes timely and transparent notification.Immediately upon detection of a breach (exact timeframe to be clarified by guidance which is expected to be released by the government)

One of the most significant requirements is the Data Protection Impact Assessment (DPIA). By default, businesses are required to conduct a DPIA in line with their data processing timeline, unless specific exemptions apply under the law mentioned at the following parts. This isn’t just a paperwork exercise; it’s a strategic review of how your data practices affect individuals and what risks you’re mitigating.

Another key obligation is the appointment of a Data Protection Officer (DPO). Medium and large enterprises must designate a qualified individual or department to oversee compliance. The DPO acts as a bridge between your business and regulators, ensuring that internal practices align with legal expectations.

Consent remains central to lawful data processing. But under the PDPL, consent must be explicit, informed, and freely given. Blanket or passive consent mechanisms will no longer suffice. Businesses must also provide clear options for individuals to withdraw consent and access or correct their data. Under current regulations in Decree 13, data subjects are allowed to give consent for one or multiple specified purposes. However, this provision is not explicitly addressed in the newly enacted PDPL. Further guidance from the Government is expected to clarify whether multi-purpose consent will continue to be permitted under the PDPL framework.

Are there any Exemptions?

Yes, and this is one of the more thoughtful aspects of the PDPL. The law recognizes that not all businesses operate at the same scale or risk level. To encourage innovation while maintaining baseline protections, the PDPL introduces transitional exemptions for smaller entities.

Startups and small businesses are exempt from Data Protection Impact Assessments Reports, and DPO appointments for five years from 1 January 2026

  • Microenterprises and household businesses may be fully exempt.

However, these exemptions do not apply if:

  • You process large volumes of personal data.
  • You provide data processing services.
  • You handle sensitive personal data directly.

This approach encourages compliance without stifling growth—a welcome move for Vietnam’s vibrant startup ecosystem.

It’s important to note that conducting Data Protection Impact Assessments Reports and appointing DPO are not the only obligations entities must fulfill under the PDPL. Other general obligations—such as establishing internal procedures and policies for personal data processing, obtaining and complying with consent, handling personal data in special contexts (such as data involving children, recruitment, employment, health and insurance, finance, advertising, online services, AI, blockchain, etc.), and notifying authorities of data breaches—apply to all entities, regardless of their size or the scale of their data processing activities.

What happens if you don’t comply?

The PDPL introduces significant penalties that reflect the seriousness of data protection violations. For example:

  • Selling personal data illegally can result in fines of up to 10 times the revenue gained or VND 3 billion, whichever is higher.
  • Violations involving cross-border data transfers may incur fines of up to 5% of the previous year’s revenue or VND 3 billion.
  • Other breaches, such as failure to obtain proper consent or notify authorities of a data breach, are subject to fines up to VND 3 billion.

For individuals, the fines are halved—but still substantial. These sanctions are designed not just to punish, but to incentivize proactive compliance and ethical data handling.

Vieter Vietnam’s perspective: What you should do now

At Vieter Vietnam, we work closely with businesses navigating regulatory change, and we know that preparing for compliance can feel complex—especially when the rules are new and evolving. The PDPL introduces a more structured approach to personal data protection, and while the law may seem technical, the steps you take now can make implementation smoother and more efficient. Below are our practical recommendations to help you prepare confidently and avoid common pitfalls.

  • Don’t wait for January 2026. Begin your internal review now. Map your data flows, assess risks, and identify gaps.
  • If you’re a startup or small business, take advantage of the grace period—but use it wisely. Build your data governance culture early to support future growth and long-term compliance.
  • If you’re already compliant with Decree 13, revisit your reports and policies, and consent mechanisms. The PDPL raises the bar.
  • Consider appointing a DPO, even if not mandatory. It sends a strong signal to regulators and customers that you take privacy seriously.
  • Stay informed. The government is expected to issue further guidance and sector-specific regulations. Monitor updates to stay compliant accordingly.

If you need help navigating the PDPL, Vieter Vietnam is here to support you. From compliance audits to training, advisory and implementation, we offer tailored solutions to help you stay ahead.