Article · June 17, 2026
Is the PDPL in force? Yes, from 01/01/2026—what firms should do now
PDPL (Law 91/2025/QH15) effective 01/01/2026. Prepare: consent, DSAR, processing contracts, security, 72-hour reporting.
Quick answer
Is the Personal Data Protection Law in force yet?
Yes. Under Law 91/2025/QH15, the Personal Data Protection Law takes effect from 01/01/2026; it was passed by the National Assembly on 26/06/2025. Before that date, businesses should continue to comply with Decree 13/2023/ND-CP and proactively upgrade their systems to meet the Law’s requirements when it takes effect.
The focus does not change: process data on a lawful basis (consent or another basis provided by law), be transparent with data subjects, implement security proportionate to risk, respect individual rights (access, rectification, restriction, deletion as provided by law), manage vendors and keep processing logs. The enforcement authority is the Ministry of Public Security (A05).
| Topic | Now (until 31/12/2025) | From 01/01/2026 | |
|---|---|---|---|
| Legal framework | Decree 13/2023/ND-CP | Law 91/2025/QH15 (PDPL) + implementing decree | |
| Compliance focus | Transparent consent, processing notices, security, data subject rights, impact assessments where required | Continue core obligations; detailed sanctions and procedures per the implementing decree | |
| Enforcement | Ministry of Public Security (A05) | Ministry of Public Security (A05), sanctions per the implementing decree; serious violations may be handled under criminal law |
What should Vietnamese businesses do now before 01/01/2026?
Start with a data inventory, choose the appropriate legal basis, standardize consent/DSAR, sign processing contracts with third parties, strengthen security, and prepare a 72-hour incident process. Goal: by 01/01/2026 you won’t need to ‘tear down and rebuild’.
Map your data (data map):
List collection sources (web/app, CRM, pixel/SDK), data types (contact, behavioral, device), purposes, storage locations, and recipients.
Define roles & legal bases:
Who is controller/co-controller/processor; for each purpose, choose consent or another legal basis under the law; avoid ‘bundling’ purposes.
Standardize consent:
Design cookie/SDK banners for true opt-in; store consent evidence (content, version, timestamp, device) and allow easy withdrawal.
Be transparent:
Update a clear privacy policy (purposes, data types, recipients, retention, individual rights, DSAR channels). Show concise notices at collection points.
DSAR end-to-end:
Set up request channels (form/email), identity verification, lookup, response, and time tracking per the law; prepare ‘cannot comply’ scenarios with valid reasons.
Contracts with vendors:
Sign data processing terms (DPA) with cloud, CDP, marketing platforms; bind purpose limitation, security, DSAR assistance, deletion/return on termination.
Risk-based security:
Apply access controls, encryption where appropriate, data classification, access logs, backups; basic testing (pentest/scan) for systems collecting personal data.
72-hour incident process:
Define ‘data breach’, set up a playbook: detect–assess risk–decide on notification–draft content–notify the authority/affected individuals within 72 hours of discovery.
Record-keeping & accountability:
Keep records of processing activities, impact assessments where required, legal decisions and advice; be ready to produce them on request.
Short training:
30–60 minute onboarding for marketing/dev/support teams on personal data, consent, handling requests, and information discipline.
Real-world examples:
- E-commerce website: separate measurement/marketing cookie groups; only fire after the user consents. Keep a consent log tied to user ID/device.
- Mobile app: load advertising SDKs only with consent; allow withdrawal in a ‘Privacy’ section.
- CRM: limit mandatory fields, configure retention; avoid manually entering sensitive data beyond announced purposes.
What should you note about penalties and 72-hour notifications?
Specific penalties will be set by the Government’s implementing decree; serious violations may be handled under criminal law. Businesses must notify the competent authority of a data breach within 72 hours of discovery, and notify affected individuals where required.
Operational practice:
- Set thresholds: when there is risk to individuals’ rights/interests, err on the side of notification; keep the decision analysis.
- Prepare notification templates: what happened, data affected, timing, impact, remediation, point of contact.
- Submission channels: follow Ministry of Public Security/A05 guidance when issued; for now, maintain a legal/IT point of contact in charge.
Quick implementation tips for engineering/marketing teams
Prioritize configuration over rewriting systems. Aim for ‘less data, clearer purposes, better control’.
- Cookie/pixel: enable opt-in; disable auto-fire; avoid ‘legitimate interest’ for behavioral marketing unless guidance clearly allows it.
- Logs/analytics: shorten retention; anonymize IP where possible; turn off detailed ‘user-map’ features if not necessary.
- Forms: split purposes (newsletter, promotions, customer support) into separate checkboxes; provide a short description next to each.
- Email/SMS: keep consent evidence per channel; add a fast unsubscribe link/instructions.
- Vendors: review SDKs/third parties, sign a DPA; block cross-border transfers beyond disclosed purposes; update the recipient list in your policy.
Tooling suggestion: consent.vn supports multi-channel consent banners, stores consent evidence, and receives data subject requests (DSAR) — suitable for SMEs and dev teams needing fast integration.
- Yes. Law 91/2025/QH15 takes effect from 01/01/2026. Before then, continue applying Decree 13/2023/ND-CP and prepare for a smooth transition.
- Comply with Decree 13, and in parallel standardize consent, transparent notices, DSAR processes, processing contracts, security, and a 72-hour incident reporting playbook.
- There is no blanket ban. However, using tracking tools triggers obligations under the law: have an appropriate legal basis (typically consent), provide clear notices, contract with the vendor, and secure the data.
- Fines will be set by the Government’s implementing decree. Serious cases may be handled under criminal law. Consult a lawyer for your specific situation.
Source: the Personal Data Protection Law (Law 91/2025/QH15) (https://thuvienphapluat.vn), Decree 13/2023/ND-CP (https://thuvienphapluat.vn), Ministry of Public Security - A05 (https://bocongan.gov.vn)
Get started — no account needed.
Ready to comply with PDPL?