Article · June 17, 2026
How Does PDPL Apply to Foreign Companies?
How PDPL applies to foreign companies handling Vietnamese users' data, when compliance is required, and what to prepare.
Quick answer
When does PDPL apply to foreign companies?
PDPL applies when a foreign company collects, stores, analyses, transfers, or exploits personal data of Vietnamese individuals, or provides goods or services to users in Vietnam as regulated. In short: if you process data of individuals in Vietnam, being “based in Singapore, the US, or the EU” does not automatically help you avoid compliance obligations.
A real-world example: an overseas SaaS sells a subscription plan to Vietnamese customers and collects email addresses, phone numbers, payment history, and product usage behavior. Even if the entire system is located outside Vietnam, the company may still have to meet obligations on notice, legal basis for processing, retention of consent evidence, handling data subject requests, and data security as required.
Why is the “outside the territory” factor important?
The key point of extraterritorial effect is that PDPL is not aimed only at domestic companies. The enforcement authority is the Ministry of Public Security — the Department of Cybersecurity and High-Tech Crime Prevention (A05), so foreign companies providing cross-border services to Vietnamese users need to treat data compliance as part of operations, not something to think about only after opening an office in Vietnam.
In practice, situations that often trigger obligations include:
- A foreign app has users in Vietnam and uses advertising/analytics SDKs.
- An international e-commerce platform collects delivery addresses in Vietnam.
- A foreign B2B company receives contact details of Vietnamese staff for demos, contracts, and customer support.
- An HR/remote work platform stores CVs, passports, ID numbers, bank account details of Vietnamese candidates or employees.
What should foreign companies prepare for compliance?
Below is a practical approach for SMEs and product/legal/engineering teams.
Define the data scope:
List the types of personal data of Vietnamese individuals you are processing: account data, identifiers, location, payment data, logs, cookies, sensitive data.
Record the legal role:
Are you a controller, processor, or joint controller? This role determines notice obligations, processing agreements, and responsibility when incidents occur.
Design transparent notices:
Update the privacy notice in Vietnamese or a language the user understands; state the purposes, types of data, data recipients, retention period, and contact method.
Manage consent and evidence:
If relying on consent, keep records of the time, the content shown, the policy version, the source of collection, and the ability to withdraw consent.
Set up a DSAR workflow:
Prepare a process to receive requests for access, correction, deletion, restriction of processing, and objection as required; assign internal SLAs.
Review vendors and offshore transfers:
Sign data protection terms with cloud, CRM, marketing, and support vendors; check data transfer flows and control mechanisms.
Prepare incident response:
Build a playbook for breach notification within 72 hours from discovery; designate legal, security, PR, and operations points of contact.
If there is no legal entity in Vietnam, are there still requirements?
Requirements may still arise under the law. Not having a subsidiary in Vietnam does not mean you are outside the scope, because the focus is on data processing activities related to Vietnamese individuals. However, the specific scope of obligations, how to work with the regulator, and the filings required will depend on the implementing guidance and the real-world situation.
For SaaS, gaming, adtech, fintech, or platform businesses with Vietnamese users, it is advisable to prepare a minimal “compliance pack” in advance:
- Vietnamese-language privacy notice.
- Record of processing activities.
- Consent log and versioning.
- Data mapping, data retention schedule.
- Incident response plan.
- Data processing agreement with vendors.
What are the penalties and risks if a foreign company does not comply?
The specific fine levels will be set by the Government's implementing decree, and there is no fixed amount at this time. In addition to administrative sanctions under the implementing decree, serious violations may be subject to criminal handling under relevant laws.
This is very important for foreign companies because the risks are not limited to fines. Practical consequences often include:
- Being required to stop certain data processing activities.
- Having to revise data collection flows, cookie banners, and signup forms.
- Losing the ability to sign contracts with Vietnamese enterprise customers due to missing compliance documentation.
- Higher dispute risk when a data breach occurs or data is used for the wrong purpose.
Where should foreign companies start?
Start with the highest-risk areas: website/app forms, cookies/SDKs, CRM, email marketing, cloud storage, and incident handling processes. If you are selling products into Vietnam, check immediately: which data is mandatory, which data is only “nice to have,” and what every tracker is collecting.
A very practical example: if your website uses cookies to measure Vietnamese user behavior, you need to consider whether that cookie creates obligations to provide notice, obtain consent, or allow preference management under the law. Do not rush to conclude that a tracker is “illegal”; identify what obligation it triggers and then fix the collection flow accordingly.
If needed, consent.vn can help you design a cookie banner, store consent evidence, and build a DSAR flow for Vietnamese users.
- When a foreign company processes personal data of Vietnamese individuals or provides goods or services to users in Vietnam as regulated.
- You may still have to comply if you collect, store, or use data of Vietnamese individuals. Not having a legal entity in Vietnam does not automatically remove the obligation.
- You should keep the privacy notice, consent log, data map, vendor contracts, DSAR process, and data breach response plan.
- Contain the incident, assess the impact scope, and prepare a data breach notification within 72 hours from discovery, as required.
Source: Luật 91/2025/QH15, Nghị định 13/2023/NĐ-CP tại thuvienphapluat.vn; A05 tại bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?