Article · June 17, 2026
Electricity, water and utilities under the PDPL: What to do?
How utilities should handle meter, customer, payment and app data to comply with the PDPL.
Quick answer
What is PDPL compliance for utilities and customer data?
This is the compliance problem when electricity, water, gas, lighting, property management or other utility providers collect and use customer data under the Personal Data Protection Law (Law 91/2025/QH15). Common data includes full name, phone number, installation address, customer ID, payment history, meter readings, images of meters, app logs and incident reports.
Note that not all data is “sensitive,” but much operational data can be directly linked to a specific household. Therefore, even when the purpose is to operate the service, you still must manage it as personal data in accordance with the regulations.
Are meter data, usage readings and payment history personal data?
Yes, if the data can be linked to a specific customer or household. For example: electricity readings tied to a customer ID, water consumption history per apartment, arrears, SMS payment reminder history, or customer service call recordings can all be personal data.
In practice, utilities usually process four groups:
- Identification data: full name, national ID number, customer ID, address, phone number.
- Service usage data: meter readings, consumption levels, incident history, service disconnection/reconnection schedules.
- Financial data: invoices, payments, refunds, arrears.
- Digital data: IP, app login logs, cookie, device, OTP, activity history.
For these data, you need to clearly define the collection purposes and scope of use—avoid “collecting for many purposes and deciding later.”
What should utilities do with customer data under the PDPL?
Start with five core tasks: notice, legal basis, data minimization, security, and third-party governance.
Map data flows:
Diagram flows from the app, call center, metering systems, payment gateways, meter-reading contractors and CRM.
Define lawful purposes:
For example: provide services, issue invoices, reconcile payments, handle complaints, prevent fraud.
Standardize customer notices:
State data types, purposes, recipients, retention periods, and how to withdraw consent or submit requests.
Set up internal controls:
Role-based access, access logging, encryption of sensitive data, and management of APIs and tokens.
Manage vendors:
Contracts with meter readers, call centers, cloud providers and e-wallets must include security and data processing clauses per regulations.
Prepare an incident process:
If data is leaked, trigger investigation, contain, record, and notify as required within 72 hours from discovery.
Do customer apps, cookies and trackers in utilities create obligations?
Yes. Customer apps often entail greater transparency obligations because they may collect cookies, analytics SDKs, device identifiers, approximate location, or in-app behavioral data. Under the regulations, you should clearly disclose the tools you use and their purposes, and not “hide” them in overly long terms.
If the app is used to:
- log in and view bills;
- send outage notifications;
- allow capturing meter readings;
- pay online;
- report incidents via chat or tickets;
then each feature entails a different data processing purpose. It’s best to group them into clear categories in the privacy notice and consent screens, rather than using a vague line like “to enhance your experience.”
What should utilities watch for when sharing data with contractors, e-wallets, and call centers?
Sharing with third parties does not mean free use. Determine whether the recipient is a processor, an independent controller, or a joint controller based on the actual business relationship, then bind them via contract and technical access controls.
Practical examples:
- Meter-reading contractors should only see the data needed for their assigned route.
- E-wallets should receive only the minimum transaction data required for reconciliation.
- Outsourced call centers need scripts and access logs under control.
- Cloud providers must include terms on storage, backup, deletion, and incident support.
If you transfer data overseas via cloud infrastructure or supporting tools, review the specific obligations under the regulations and seek legal advice when the data structure is complex.
Quick checklist for operations and engineering teams
| Category | To-do | Example in utilities |
|---|---|---|
| Notice | State purposes, data types, recipients | "Collect phone numbers to send bills and outage notifications" |
| Consent/legal basis | Store evidence, no defaults | Separate checkbox for marketing SMS, different from operational notices |
| Security | MFA, encryption, access logging | Staff only view data for their assigned area |
| Contracts | Bind data processing | Meter-reading contractors may not reuse data |
| Incidents | 72-hour response playbook | Leakage of arrears list via an Excel file |
What should you do if customer data is breached?
Upon detecting an incident, immediately isolate the system, determine the scope of impact, record the time of discovery, and prepare notifications as required within 72 hours. Also retain logs, screenshots, a list of affected systems, and remediation decisions to support internal investigation and work with the competent authority.
The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-tech Crime Prevention (A05). Specific penalties will follow the Government’s guiding decrees; serious violations may be subject to criminal prosecution.
- Not all data requires consent in all cases. You must identify the correct legal basis under the regulations, but you still need to provide clear notice and keep appropriate evidence.
- Yes, if the readings are linked to a specific customer or household. When combined with a customer ID, address or payment history, identification becomes even easier.
- List the tools, purposes, data collected, and recipients in the user notice. If you track behavior or identify devices, review consent mechanisms separately as required.
- Within 72 hours from discovery, as required. Businesses should prepare an incident response procedure and a contact point before risks materialize.
If you’re building a customer app, cookie banner, or a process to store consent evidence, consent.vn can help standardize it in a way that’s easy for product and engineering teams to implement.
Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — https://thuvienphapluat.vn; Ministry of Public Security (A05) — https://bocongan.gov.vn
Get started — set up in 5 minutes.
Deploy PDPL solutions for your business?