Article · June 17, 2026

What acts are prohibited under the Personal Data Protection Law?

Explains prohibited acts under the Personal Data Protection Law: data trading, processing without legal basis, data leaks, and how to avoid.

consent.vn Editorial6 min read

Quick answer

Prohibited acts under the Personal Data Protection Law include the unlawful trading of data, processing data without a legal basis, exposing or disclosing personal data, and other privacy-infringing acts as prescribed. Businesses should review their data collection, storage, sharing, and logging to avoid compliance risks.

What acts are prohibited under the Personal Data Protection Law?

Prohibited acts under the personal data protection law are actions that collect, use, share, trade, or expose personal data in contravention of regulations. For Vietnamese businesses, risks usually fall into three groups: lacking a legal basis for processing, transferring data to third parties for incompatible purposes, and data leakage due to weak configuration or operations.

As a rule, personal data may only be processed when there is a lawful basis and for the purposes that have been notified. If a company collects customer data from a marketing form, then uses it for telesales, sends it to an advertising partner, or sells the customer list, this is a very high-risk area and may be considered a violation under the regulations.

How is unlawful data trading prohibited?

Unlawful data trading is the most notable conduct because it often entails multiple violations: lacking valid consent, failing to notify data subjects, failing to control the data recipient, and lacking clear processing/sharing contracts.

A real-life example in Vietnam: an e-commerce marketplace buys files containing phone numbers, names, and purchase history from an external source for remarketing. If that data was not lawfully collected and transferred, the business may have to justify the legal basis for processing, the data source, and the responsibilities of the related parties.

You should not assume that simply “anonymizing” makes it safe. Data can still be personal data if the recipient can identify the user, especially when combined with phone numbers, email addresses, customer IDs, or transaction history.

Is processing data without a legal basis considered a violation?

Yes. This is one of the prohibited acts under personal data protection law if a business processes data without an appropriate legal basis under the regulations.

Common lawful bases in business operations include valid consent, performance of a contract, legal obligation, or other bases under applicable law. If a company collects data from a landing page but the form does not clearly state the purpose; or the consent checkbox is bundled together with marketing terms; or there is no evidence retained of consent, subsequent processing is very likely to be challenged.

Especially for SMEs and dev teams, common mistakes include:

  • collecting more than necessary;
  • using one form for multiple purposes;
  • not separating consent for marketing, transferring data to partners, and cookie tracking;
  • lacking a mechanism to withdraw consent or delete data upon user request.
  1. Define processing purposes:

    State clearly why you collect data: account creation, delivery, customer support, or marketing.

  2. Assign a lawful basis to each purpose:

    Do not bundle everything into one checkbox. Each purpose should have its own basis under the regulations.

  3. Data minimization:

    Only collect fields that are truly necessary. If you don’t need date of birth, don’t ask for it.

  4. Store evidence of consent:

    Record the time, consent content, privacy notice version, and IP/user agent if needed.

  5. Review third parties:

    If you use a CRM, email marketing, analytics, or chatbot, review processing roles and data sharing terms.

  6. Set up a DSAR process:

    Have an internal flow to receive access, rectification, deletion, and consent withdrawal requests and respond on time.

Is exposing personal data a prohibited act?

Yes. Exposing personal data, unlawful disclosure, or allowing data to leak due to poor management are serious risks under the regulations.

In practice, data often leaks because of:

  • sending the wrong customer file via email/drive;
  • leaving a public cloud bucket containing images of citizen ID cards, orders, phone numbers;
  • shared admin accounts;
  • application logs that directly record tokens, passwords, OTP codes;
  • departed staff still having system access.

If an incident is detected, the business should trigger the incident response process and notify of the data breach within 72 hours from discovery, as required. At the same time, isolate systems, retain logs, determine the scope of impact, and assess whether notification to affected parties is required.

ScenarioLegal riskWhat to do
Buy a customer file from an external source to run adsMay constitute unlawful processing/data tradingStop using it, check the source, keep evidence of provenance
Form has a single “agree to all” checkboxNo clear legal basis for each purposeSplit consent by purpose, log the consent
Accidentally sending a customer list via emailPersonal data disclosureRevoke access, record the incident, assess the 72-hour notification
Use analytics/remarketing toolsTriggers transparency and third-party management obligationsUpdate notices, cookie banner, contracts and configuration

What should businesses do to avoid violations?

The most practical approach is to make compliance a part of product and operational processes, rather than waiting to react when incidents occur.

Minimum checklist for SMEs:

  • review the privacy notice and cookie banner;
  • map end-to-end data flows from forms, apps, and CRM to vendors;
  • separate processing purposes and legal bases;
  • restrict access based on roles;
  • encrypt sensitive data and manage secrets properly;
  • establish a process for receiving data subject requests;
  • train customer support, sales, marketing, and dev staff on personal data.

Specific penalties will be set by the Government’s guiding decree; for serious violations, businesses may also face criminal liability under the law. Therefore, if you are using a CRM, email marketing tools, pixels, chatbots, or transferring data to partners, you should review this early with your lawyers and engineering team.

Yes. Unlawful data trading is a very high-risk category and can be sanctioned under the regulations, especially if there is no legal basis and data subjects are not notified.
Not necessarily. Consent must be valid, separated by purpose, and supported by evidence. If the checkbox is bundled or not transparent, it can still be deemed insufficient.
It can be. Even if it is an operational error, the business must handle the incident, mitigate harm, and consider the obligation to notify of a data breach within 72 hours from discovery.
You should not assume so. The issue is that such tools trigger obligations for transparency, obtaining appropriate consent, managing cookies, and controlling third parties under the regulations.

If you need templates for a cookie banner, consent logs, or a DSAR process for your website/app, consent.vn can help standardize them for easy implementation by product and dev teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15), Decree 13/2023/ND-CP on thuvienphapluat.vn; Ministry of Public Security (A05) on bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started