Article · June 17, 2026
What are the lawful and fair processing principles under the PDPL?
Explains lawful and fair processing under the PDPL, legal bases, violation examples, and how businesses can apply them.
Quick answer
What are the lawful and fair processing principles under the PDPL?
In short: you may process personal data only when you have a legal basis under the rules, and your processing must be transparent, not “gaming” the system with vague language or deceptive design. The Personal Data Protection Law (Law 91/2025/QH15), effective 01/01/2026, replaces/upgrades the previous framework of Decree 13/2023/ND-CP.
“Fair” here is not a moral slogan. It is a practical requirement: if you collect a phone number for delivery, you cannot quietly reuse it for SMS marketing; if you request data to create an account, you cannot scoop up unnecessary data and then sell/share it with third parties without the user’s knowledge.
What are the lawful bases for processing under the PDPL?
Businesses must determine the legal basis before touching data. In practice, the most common are: valid consent from the data subject; necessary to perform a contract; necessary to comply with a legal obligation; protection of the vital interests of an individual; or other bases provided by law for specific situations.
The key point is that the basis cannot be “box-ticked.” For example, a fintech app cannot take a single checkbox “I agree to all purposes” and use it once for everything: identity verification, credit scoring, sharing with advertising partners, long-term retention. Each purpose must be described clearly, and if the basis is consent, you must ensure users know what they are consenting to.
Identify the real purposes:
List each processing activity: collection, storage, analysis, sharing, deletion.
Assign a legal basis to each purpose:
Which is based on contract, legal obligation, or consent—state it explicitly.
Check necessity:
Collect only the minimum data needed for the purpose.
Write a transparent notice:
Be concise and clear, avoid vague terms like “improve experience” unless you explain specifically.
Keep evidence:
Record the timestamp, notice content, consent version, and change logs.
Review third parties:
If you use a vendor/CDP/ads tracker, know where data goes, who receives it, and for what purpose.
What counts as fair, non-deceptive data processing?
Fair means users are not forced into “agreeing because there’s no alternative,” or steered by misleading design. Common red flags:
- Bundling multiple purposes into a single button, making it impossible for users to tell what is mandatory and what is optional.
- Using vague language like “trusted partners” without naming who they are.
- Burying data-sharing terms in a long, hard-to-read policy and calling that adequate notice.
- Pre-ticking consent boxes for advertising, behavioral analytics, or data sharing.
- Requesting employee/customer data beyond actual need, then using it for another purpose.
A real-world example in Vietnam: an e-commerce marketplace collects a phone number to arrange delivery. If the marketing team later sends weekly promotional messages without an appropriate legal basis and without clear advance notice, that risks violating the lawful and fair processing principles.
Examples of violating the PDPL’s lawful and fair processing principles
Some situations that commonly “trip up” organizations:
- Recruitment app requires candidates to grant access to contacts and location even though it’s unnecessary for screening.
- E-commerce website uses pixels/SDKs to track behavior but does not clearly explain the purposes and recipients of the data.
- Clinic shares patient records with an insurance partner without an appropriate legal basis.
- B2B company buys email lists and sends bulk marketing without a lawful basis for that outreach.
- Internal HR stores rejected CVs indefinitely, with no deletion policy or retention limits.
These examples do not automatically determine criminal liability or specific penalties. Fines will follow the Government’s guiding decree; serious violations may be subject to criminal handling as provided by law. The enforcing authority is the Ministry of Public Security—Department of Cybersecurity and High-Tech Crime Prevention (A05).
What should businesses do to avoid violations?
If you are an SME or a technical team, prioritize the following four tasks:
- Clearly separate mandatory and optional purposes in your forms/flows.
- Review your privacy notice so users understand who processes what, for how long, and with whom it is shared.
- Log consent and policy changes to have evidence for audits.
- Check all trackers, SDKs, CRM, CDP, and service providers to see whether they cause processing beyond the notified scope.
If the risk is high or the data is sensitive, have legal counsel or your legal team review before going live. In digital systems, fixing the consent flow after deployment is often far more expensive than doing it right from the start.
How does this principle relate to data breach notification?
Once you process data, you must also prepare for leaks. If a data breach occurs, the notification deadline is within 72 hours from detection. Therefore, lawful and fair processing is not just paper compliance; it underpins your ability to control operational risk and respond to incidents.
- No. A checkbox is only one part. You also need clear purposes, transparent information, data minimization, and properly stored evidence as required.
- You cannot conclude automatically. It triggers obligations to provide notice, obtain an appropriate legal basis, and control data recipients as required.
- It depends. If the processing is truly necessary for the contract, you can rely on that basis, but you must still provide transparent notice and use the data only within the necessary scope.
- Specific fines will follow the Government’s guiding decree; in serious cases, criminal liability may apply as provided by law.
If you are implementing a cookie banner, consent evidence storage, or DSAR procedures, consent.vn can help standardize your flows and logs to make proof easier when needed.
Source: the Personal Data Protection Law (Law 91/2025/QH15) (thuvienphapluat.vn); Decree 13/2023/ND-CP (thuvienphapluat.vn); Ministry of Public Security—Department of Cybersecurity and High-Tech Crime Prevention (A05) (bocongan.gov.vn)
Get started — no account needed.
Ready to comply with PDPL?