Personal Data Protection Law (Law No. 91/2025/QH15)
Vietnam's Personal Data Protection Law (Law No. 91/2025/QH15) is the country's current comprehensive personal data protection framework. The law was adopted on 26 June 2025 and came into force on 1 January 2026, replacing the previous framework centred on Decree 13/2023/ND-CP. Decree 356/2025/ND-CP, also effective from 1 January 2026, provides detailed implementation rules.
The law regulates how organisations collect, process, use, store, transfer and protect personal data. It applies to Vietnamese organisations and individuals, foreign organisations and individuals in Vietnam, and certain foreign parties involved in processing personal data of Vietnamese citizens and qualifying persons of Vietnamese origin.
For businesses operating websites, applications, digital services, e-commerce platforms or marketing technologies in Vietnam, compliance requires more than simply displaying a privacy notice. Organisations need appropriate lawful grounds for processing, transparent information practices, appropriate security controls, evidence of consent where consent is relied upon, data-subject rights processes, and controls for cross-border processing.
Vietnam's current personal data protection framework is based on:
The law recognises consent as an important legal basis for processing, but consent is not the only possible basis for processing personal data. Organisations should identify the applicable legal basis and meet the corresponding statutory requirements before processing data.
Where consent is required or relied upon, organisations should ensure that consent is appropriately obtained and can be demonstrated. Decree 356/2025/ND-CP provides for reproducible forms of consent, including written and electronic methods.
| Requirement | Vietnam |
|---|---|
| Primary law | Law No. 91/2025/QH15 |
| Implementation decree | Decree No. 356/2025/ND-CP |
| Effective date | 1 January 2026 |
| Previous framework | Decree 13/2023/ND-CP |
| Regulated data | Basic and sensitive personal data |
| Consent | One lawful basis; not universal |
| International transfers | Regulated |
| Impact assessments | Required in specified circumstances |
| Breach notification | 72 hours for qualifying violations |
| Maximum specified administrative fine | Up to 5% of previous-year revenue for specified cross-border violations; up to VND 3 billion for other specified violations |
| Primary implementation authority | Ministry of Public Security |
Vietnam
In force since 1 January 2026
Asia & Africa
The law applies to:
This means organisations outside Vietnam may still need to assess their obligations where their activities involve personal data falling within the law's scope.
Businesses should therefore assess their processing activities rather than relying solely on their physical location.
Vietnam's Personal Data Protection Law establishes significant administrative penalty ceilings for specified violations.
For certain cross-border personal-data violations, the maximum administrative fine can reach 5% of the previous year's revenue. For other specified administrative violations, the maximum fine is VND 3 billion. The statutory framework provides that the maximum fine for an individual committing the same violation is generally one-half of the organisational maximum.
Businesses should assess potential exposure based on the specific violation, applicable implementing regulations and the facts of the processing activity.
Vietnam's law establishes several core principles for processing personal data.
Organisations should ensure that personal data is:
These principles mean privacy compliance should be integrated into an organisation's broader data governance and security programme.
Vietnam's Personal Data Protection Law defines personal data broadly as digital data or information in another form that identifies or helps identify a specific individual.
The framework distinguishes between:
Basic personal data covers common personal information and background details used in transactions and social relationships and included within categories determined by the Government.
Examples may include information used to identify or communicate with an individual, depending on the applicable classification.
Sensitive personal data is personal data associated with an individual's privacy rights where infringement could directly affect the legitimate rights and interests of relevant parties.
The detailed classification of sensitive personal data is determined by Government regulations.
Organisations should therefore maintain a data inventory that identifies both the type of personal data processed and whether it falls within a specially protected category.
Consent is not a blanket requirement for every processing activity under Vietnam's current law.
The law defines consent as permission from a personal-data subject for processing their personal data, except where the law provides otherwise.
Accordingly, organisations should determine:
This is an important change from describing Vietnam's framework as simply requiring consent for all processing.
Where consent is the applicable legal basis, businesses should design their consent mechanisms so that they are clear, demonstrable and appropriately documented.
Under the current framework:
Decree 356/2025/ND-CP recognises methods including written consent, recorded calls, SMS, email, websites, platforms, applications and other methods capable of reproduction or verification.
A consent banner alone does not establish complete compliance.
Businesses should connect consent management with:
Organisations should provide individuals with appropriate information about the processing of their personal data.
A practical privacy notice should explain, where relevant:
For websites and applications, transparency should extend to cookies, analytics, advertising technologies, tracking technologies and other online identifiers where they involve personal data.
Vietnam's Personal Data Protection Law provides rights for personal-data subjects and establishes corresponding responsibilities for organisations processing personal data.
Depending on the applicable circumstances, organisations should be prepared to manage requests relating to:
Organisations should establish an internal workflow for receiving, authenticating, tracking and responding to data-subject requests within the applicable statutory periods.
Processing personal data relating to children requires additional safeguards under Vietnam's personal data protection framework.
Businesses that provide services to children or knowingly process children's personal data should assess:
Child-focused services should incorporate these requirements into product design rather than treating them as an afterthought.
Sensitive personal data receives enhanced protection under Vietnam's framework.
Businesses processing sensitive personal data should identify the relevant category and assess whether additional obligations apply to:
A privacy programme should maintain a clear inventory showing where sensitive personal data is collected, processed, stored or transferred.
Vietnam's current framework includes impact-assessment requirements for specified processing activities.
Organisations should assess whether their processing requires a personal data processing impact assessment dossier and ensure that required documentation is maintained and submitted in accordance with applicable rules.
An effective assessment should consider:
Cross-border processing is an important compliance area under Vietnam's current law.
Decree 356/2025/ND-CP defines cross-border transfer activities broadly, including circumstances involving the movement or processing of personal data collected or stored in Vietnam through overseas infrastructure, foreign cloud services or overseas recipients.
Businesses using:
should assess whether their activities constitute regulated cross-border processing.
Depending on the circumstances, an organisation may need to prepare or maintain a cross-border personal data transfer impact assessment dossier or comply with another applicable statutory mechanism.
Organisations processing personal data should implement appropriate organisational, technical and human safeguards.
Security measures may include:
Security should be proportionate to the nature and risks associated with the data being processed.
Vietnam's current Personal Data Protection Law establishes a 72-hour notification requirement for qualifying personal-data violations after the relevant organisation discovers the violation.
The requirement applies to qualifying violations that may harm matters such as national defence or security, social order and safety, life or health, honour and dignity, or property, subject to the statutory conditions.
Organisations should therefore maintain an incident-response process capable of:
A privacy incident-management process should be connected to the organisation's broader cybersecurity incident-response programme.
Businesses should clearly define their roles when processing personal data.
Depending on the activity, an organisation may act as:
Contracts with processors and vendors should clearly establish:
Vietnam's framework requires personal data to be stored for an appropriate period corresponding to the purpose of processing, unless another law provides otherwise.
Organisations should therefore maintain documented retention schedules covering:
Retention should not continue indefinitely simply because data is technically inexpensive to store.
Businesses operating websites in Vietnam should assess their cookies and tracking technologies as part of their personal-data compliance programme.
This includes:
Consent requirements depend on the applicable legal basis and circumstances. Organisations should not assume that every cookie requires consent, but they should also avoid deploying personal-data processing without establishing the appropriate legal basis and safeguards.
Marketing activities frequently involve personal data and should therefore be incorporated into an organisation's privacy compliance programme.
Businesses should assess:
Marketing consent should be clearly separated from unrelated terms where consent is required.
Businesses using AI, automated decision-making, profiling or behavioural analytics should assess whether these activities involve personal data and whether additional requirements apply.
A privacy assessment should consider:
Organisations should document their AI and automated-processing use cases as part of their broader personal-data governance programme.
Vietnam's Personal Data Protection Law contains transitional compliance provisions for certain small enterprises and startups.
Under the law, eligible small enterprises and startups may choose whether to implement certain provisions for a five-year period from the law's effective date, subject to statutory exceptions. The exemption does not generally apply where the business provides personal-data processing services, directly processes sensitive personal data, or processes personal data relating to large numbers of data subjects.
Decree 356/2025/ND-CP provides additional detail concerning the relevant thresholds and exemptions.
Businesses should therefore determine eligibility rather than assuming that all startups or small businesses are automatically exempt from Vietnam's privacy requirements.
Vietnam's privacy framework changed significantly on 1 January 2026.
The new Personal Data Protection Law expressly provides transitional treatment for certain processing activities that were already being carried out with consent or agreements under Decree 13/2023/ND-CP before the new law took effect. Certain previously submitted impact-assessment dossiers may also continue under the transitional rules.
At the same time, Decree 356/2025/ND-CP states that Decree 13/2023/ND-CP ceases to have effect from 1 January 2026.
Therefore, businesses should update their compliance programmes rather than continuing to rely exclusively on guidance designed for the former Decree 13 regime.
Use this checklist to review your organisation's Vietnam privacy programme:
For organisations operating websites, apps and digital platforms in Vietnam, personal-data compliance increasingly requires coordination between privacy, security, legal, marketing and technology teams.
A modern compliance programme should therefore combine:
Legal basis + transparency + consent management + data governance + security + rights management + transfer controls + audit evidence.
ConsentX can support the consent-management and website privacy layer while organisations maintain the broader legal and organisational controls required by Vietnam's framework.
The Personal Data Protection Law applies within Vietnam's legal framework and also contains provisions affecting certain foreign organisations and individuals involved in the processing of covered personal data.
Businesses operating internationally may also need to assess:
Applicable requirements depend on the organisation, processing activity, individuals involved and jurisdiction.
ConsentX helps organisations operationalise key elements of their personal-data compliance programme.
Scan your website to identify cookies, scripts, pixels and tracking technologies that may process personal data.
Use prior-script blocking to prevent selected non-essential technologies from executing before the applicable permission is obtained.
Deploy configurable consent experiences and capture user choices through an auditable consent-management system.
Create consent records that can help demonstrate:
Provide workflows for managing consent withdrawal and data-subject requests.
Use region-based configuration to provide different consent and privacy experiences depending on applicable legal requirements.
Connect website consent management with broader privacy processes, including data discovery, records, rights requests and compliance evidence.
ConsentX can support the consent-management and website privacy layer while organisations maintain the broader legal and organisational controls required by Vietnam's framework.
Run a ConsentX privacy scan to identify cookies, trackers, scripts and third-party technologies operating on your website.
Identify what personal data is collected, why it is collected, where it is stored and which vendors receive it.
Determine whether processing relies on consent or another legal basis available under Vietnam's law.
Where consent is required, implement a clear consent mechanism that records the user's decision and provides the relevant information.
Configure prior-script blocking so selected cookies and trackers do not execute before the applicable permission is obtained.
Maintain structured consent records that can be used as evidence of the user's choice.
Provide users with practical mechanisms for withdrawing consent and exercising applicable data-subject rights.
Identify overseas vendors, cloud services, analytics providers and other recipients involved in processing Vietnamese personal data.
Determine whether your processing or cross-border activities require an impact assessment dossier under the current law and implementing decree.
Privacy compliance is ongoing. Regularly rescan your website, review vendors, update privacy notices and adjust consent configurations when processing activities change.
This page provides a plain-English overview of Vietnam's Personal Data Protection Law (Law No. 91/2025/QH15) and Decree 356/2025/ND-CP for general informational purposes. It is not legal advice.
Obligations can vary depending on the organisation, the processing activity, the individuals involved and the jurisdiction. Organisations should verify current requirements against the law, its implementing regulations and any sector-specific rules, and obtain qualified Vietnamese legal advice where necessary.