Guide · June 17, 2026
Does a Business Household Have to Comply with PDPL?
Do business households and online sellers have to comply with PDPL? See minimum duties, examples, and an actionable checklist.
Quick answer
Hộ kinh doanh có phải tuân thủ PDPL không?
Yes, if you collect or process personal data of customers, employees, or partners, then whether you are a business household or an individual online seller, obligations arise under the regulations. PDPL does not target only large enterprises; in practice, online shops, livestream sellers, and coffee shops taking bookings via Zalo/Google Form can all come into contact with personal data.
The key point to remember is that the law does not “ban” you from keeping a customer’s phone number for delivery, but it requires you to do it properly: have a clear purpose, provide transparent notice, use the data only for the stated purpose, and apply data protection measures. If you have more sensitive activities such as sharing data with third parties, running retargeting ads, or using customer photos/videos, you need to review the obligations carefully and should ask a lawyer if you are unsure.
Hộ kinh doanh online thường phải xử lý những dữ liệu nào?
Many people think they are “only selling products,” but in reality they are often processing personal data every day. For example:
- Names, phone numbers, and delivery addresses on orders
- Chat content in Messenger/Zalo
- Email addresses and login accounts when creating member accounts
- Customer photos taken with products, feedback that identifies an individual
- Payment information, purchase history, purchase frequency
Even if you use a third-party order form, paper order notes, Excel files, POS software, CRM, or chat automation, data protection obligations can still arise because you are the party deciding the purpose and way the data is used.
Làm gì tối thiểu để tuân thủ PDPL?
You do not need to deploy a complex system from day one. For a business household or an individual selling online, do at least the following 5 things.
Identify the data you are collecting:
List the types of data such as names, phone numbers, addresses, chat content, photos, payment information. If you do not know what you are holding, you cannot protect it.
Notify customers:
State clearly why you collect the data, how long you keep it, who may receive it, and how customers can contact you to request correction/deletion. The notice can be placed directly on the form, checkout page, or order confirmation message.
Ask for consent only when needed:
Not every case requires consent in the same way, but if you use data for marketing, remarketing, or sharing with partners not necessary for the order, obtain clear consent and keep evidence.
Limit who can view the data:
Only the shop owner, delivery staff, accountant, or necessary logistics provider should have access. Do not send customer files in public chat groups.
Have a process for handling requests and incidents:
When customers request data updates/deletion, or when a data leak is detected, you must know who handles it, how to respond, and if it is a data breach, notify within 72 hours from detection.
Ví dụ thực tế: shop online cần làm tối thiểu thế nào?
Suppose you sell clothing on Facebook and receive orders via Google Form. Each order includes a name, phone number, address, and size notes. The minimum approach should be:
- Add a notice right on the form: “The information you provide will be used to confirm and deliver your order, support exchanges/returns, and customer care.”
- Include an opt-in checkbox if you want to use the phone number for after-sales care or sending promotions.
- Do not use the old customer list for remarketing unless you have an appropriate legal basis and have given clear notice.
- Store order files in a password-protected location, with access permissions, and do not make Drive links public.
- When a customer messages “delete my information,” you need a process to handle and respond.
If the shop has order-closing staff, logistics providers, or outsourced accountants, you should identify who is allowed to view which data. This is the part SMEs most often overlook.
Hộ kinh doanh cần chuẩn bị tài liệu gì?
You do not need a thick “legal dossier,” but you should have a few minimum documents to stay on track:
- A short privacy notice for customers
- A consent form if you have activities that require clear consent
- A list of data recipients: logistics providers, payment gateways, accountants, CRM
- A process for handling customer requests: view, correct, delete, withdraw consent
- A process for handling data leak incidents
If you are using a cookie banner on your website, keeping consent evidence, or need to handle DSAR, consent.vn can help you standardize this in a more practical way for SMEs.
Hộ kinh doanh vi phạm thì bị xử lý thế nào?
The specific fines will be set by the Government’s implementing decree; there is no fixed amount that can be stated immediately at this time. However, serious violations may be subject to criminal handling under the regulations. The enforcement authority is the Ministry of Public Security (A05), through the Department of Cybersecurity and High-Tech Crime Prevention and Control (A05).
For small business households, the risk usually does not come from “intentional violations,” but from the habit of storing data carelessly, sharing customer files too widely, or using data for marketing without notice. This is something that should be addressed early because the cost of doing it right is always lower than the cost of handling an incident.
- It may. As soon as you collect names, phone numbers, addresses, messages, or customer photos to close orders, deliver goods, or provide after-sales care, obligations arise under the regulations.
- Yes, it is advisable. At minimum, you need a short notice stating what data you collect, what you use it for, who receives it, and how customers can contact you to request deletion or correction.
- When you use the data beyond the necessary transaction purpose, for example sending promotions, running remarketing, or sharing with other parties not necessary to complete the order, under the regulations.
- Contain it immediately, change passwords and lock access rights, assess the scope of impact, and then notify the data breach within 72 hours from detection if it is a reportable case.
Checklist tối thiểu cho hộ kinh doanh online là gì?
If you need a short checklist to act on this week, start with these 6 things: write a 5–7 line privacy notice, add a consent checkbox when needed, review who currently holds customer files, enable passwords for where data is stored, prepare a template response for deletion/correction requests, and set up an incident response process. Doing this is already much better than most shops today.
Source: Luật 91/2025/QH15 and Nghị định 13/2023/NĐ-CP at thuvienphapluat.vn; enforcement authority A05 at bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?