Article · June 17, 2026

How study abroad consultancies handle student data under the PDPL

Guidance for study abroad consultancies on handling student files, financials, passports, and sharing with foreign schools under the PDPL.

consent.vn Editorial7 min read

Quick answer

Study abroad consultancies often process highly sensitive personal data: student files, parent information, passports, finances, and sometimes children’s data. Under the Personal Data Protection Law (Law 91/2025/QH15), businesses must define the correct purposes, have a legal basis for processing, clearly notify about overseas sharing, and retain evidence of consent where needed.

What should study abroad consultancies keep in mind about student data under the PDPL?

The short answer: almost every step in the study abroad advisory process touches personal data, and many cases involve children’s data, financial data, passports, visas, transcripts, letters of recommendation, and health status. Therefore, companies should not treat this merely as an “admissions file,” but must manage it as a controlled data processing workflow.

A real example: a typical study abroad file includes full name, date of birth, passport number, academic history, grades, proof of finances, parent phone number, email, a headshot, a scan of the birth certificate, and sometimes guardian information. If you send this file to a foreign school, recruitment agent, credential verification body, or a visa service provider, you have shared data and must ensure compliance.

Which data in a study abroad file is usually most sensitive?

  • Children’s data: files for underage students, guardian information.
  • Financial data: bank statements, balances, proof of parents’ income.
  • Identification data: passport, citizen ID card, photo, signature.
  • Academic data: transcripts, grade reports, recommendation letters, essays.
  • Cross-border data: when sending to schools, partners, or systems located abroad.

What legal basis should a study abroad consultancy rely on to process student files?

First, you must determine the purpose for which you are processing data: advising on academic pathways, submitting applications, requesting offers, applying for visas, booking accommodation, or post-enrollment support. Each purpose may require a different legal basis under the regulations.

For data of underage students, a prudent practice is to obtain consent from the data subject within the limits of the law and, typically, consent/confirmation from a parent or legal guardian as required for children’s data. You should design the form with separate consents: consent to receive consulting, consent to share with foreign schools, consent to process children’s data, and consent to receive marketing.

If the company retains files “for later use” or to forward to multiple schools and countries, do not bundle everything into a single checkbox. Under the rules, each purpose should have its own layer of notice and its own consent record.

  1. Map data flows:

    list which files are collected, who enters them, who views them, and who exports them externally.

  2. Classify data:

    flag children’s data, financial data, passport data, and other sensitive data.

  3. Fix the legal basis:

    determine for each purpose whether consent is required and whether a parent/guardian is needed.

  4. Draft transparent notices:

    clearly state purposes, recipients, retention periods, and any cross-border transfers.

  5. Retain evidence:

    store consent logs, form versions, time of signature, IP address, or appropriate system trails.

  6. Prepare a DSAR process:

    have a way to receive requests to access, rectify, delete, or withdraw consent.

What should you watch out for when sharing student files with foreign schools?

Yes. This is something many consultancies do quite “naturally,” but it is where the biggest risks arise. When you send files to a foreign school, you are transferring data outside your company and possibly outside Vietnam.

You should inform customers in advance: which data will be sent, to whom, to which country, for what purpose, and who is responsible for contact when the student wants to withdraw consent or request deletion. If the foreign school requires a separate form, review the recipient’s privacy terms and avoid sending unnecessary extra data.

A practical rule: send only the file components the school requests. If the school only needs the transcript and passport, do not automatically include bank statements, parents’ IDs, or lists of relatives.

How should a study abroad consultancy design its PDPL process?

Ideally, build the PDPL into your admissions workflow, not as final add-on paperwork. For SMEs, you do not need a complex apparatus, but you must have at least these controls: collection forms, a banner/notice text, internal access controls, an audit trail for sharing, and a process to handle data requests.

For example, a counselor should not export an entire student file via a personal email account. Instead, the system should enforce role-based access; sensitive files should be stored in a controlled repository; and outbound sending should use an approved channel.

If your company uses a website to capture leads, chat widgets, tracking forms, or ad pixels, remember these tools often trigger notification and consent obligations under the regulations. Do not assume that “it’s just marketing” and PDPL does not apply.

How can violations in the study abroad sector be handled?

Specific fines are currently set by the Government’s implementing decrees; the statute does not fix amounts. In addition to administrative penalties under the implementing decree, serious violations may lead to criminal liability. The enforcement authority is the Ministry of Public Security (A05).

One situation needing special attention is a leak of student files: passport scans, bank statements, and parent contact details mistakenly sent to a third party. If an incident exposes personal data, the company must activate its incident response and notify of the breach within 72 hours of discovery.

What should a short policy template for a study abroad consultancy include?

You should include at least a clear consent notice on the registration form. For example:

“I consent to [Company Name] collecting, using, storing, and sharing my/the student’s personal data for whom I act on behalf for the purposes of study abroad consulting, file preparation, and working with schools/visa processing bodies inside and outside Vietnam in accordance with the law. I understand that I may withdraw consent to the extent permitted by law.”

For cases where the student is a child, add a line for the parent/guardian to confirm representative authority and responsibility for providing accurate information.

When collecting, using, storing, or sharing student files for consulting, applying to schools, visas, marketing, or transferring data outside the company, you should determine the legal basis and obtain consent as required where applicable.
Yes. For children’s data, design a process that involves/obtains confirmation from a parent or guardian as required, rather than relying solely on a student’s single tickbox.
You should clearly notify the data types, recipient, destination country, purpose, and retention period. If data will be transferred abroad, check the applicable requirements and consult a lawyer if unsure.
This may be a personal data breach. Record it, contain it, remediate, and notify within 72 hours of discovery as required.

If you are building a study abroad registration system, consider adding a cookie banner, consent evidence, and a DSAR flow from the start to avoid rework later.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn; Ministry of Public Security (A05) — bocongan.gov.vn

Get started — set up in 5 minutes.

Deploy PDPL solutions for your business?

Get started