Article · June 17, 2026

What is the scope of the Personal Data Protection Law?

Scope of the Personal Data Protection Law: data, processing, extraterritorial effect, exceptions.

consent.vn Editorial6 min read

Quick answer

The Personal Data Protection Law (Law 91/2025/QH15) has very broad application: it covers personal data and all data processing activities, both within and outside Vietnam if they relate to individuals in Vietnam. Businesses should carefully review the types of data they collect, how they process it, and the statutory exceptions.

What does the scope of the Personal Data Protection Law cover?

The Law applies to personal data and all related personal data processing activities. In short, if your business collects, records, stores, analyzes, shares, transfers, or deletes an individual’s data, it likely falls within scope.

Note that the Personal Data Protection Law (Law 91/2025/QH15) was passed on 26/06/2025, takes effect from 01/01/2026, and upgrades/replaces the earlier framework under Decree 13/2023/ND-CP. The enforcing authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05).

What types of data does the Personal Data Protection Law apply to?

The Law is not limited to “sensitive data” but covers personal data in general. For SMEs, common categories include:

  • Identifying information: full name, phone number, email, national ID (CCCD), date of birth.
  • Account and transaction data: bank account numbers, payment history, invoices.
  • Digital behavioral data: cookie, device ID, IP, access logs, website/app behavior.
  • HR data: candidate profiles, employment contracts, performance reviews.
  • Customer data: purchase history, support requests, feedback, complaints.

If you operate an e-commerce website, a CRM, a booking app, an HRM system, or a SaaS platform, you are almost certainly processing personal data within the meaning of the Law.

Data categoryReal-world examplesCommon compliance risks
Identifying datacustomer name, phone number, emaillack of notice, lack of legal basis
Location/behavioral dataIP, cookie, access logsno banner/no clear capture of consent
Financial dataaccount numbers, payment historyuncontrolled sharing with third parties
HR dataCV, national ID (CCCD), payroll recordsexcessive retention, weak access controls
Sensitive datahealth, biometrics, religionlack of enhanced safeguards

Which processing activities fall within scope?

The Law applies to all “data processing” in the practical sense, not just storage. For developers and product teams, even a small technical event may constitute data processing.

Common activities include:

  • Collecting data via forms, apps, chatbots, call centers.
  • Recording and storing it in databases, files, cloud, CRM.
  • Using data for authentication, customer care, marketing, analytics.
  • Sharing data with partners, vendors, carriers, payment gateways.
  • Transferring data overseas via SaaS, cloud, email, analytics.
  • Deleting, destroying, anonymizing, backing up, restoring data.
  1. Identify data touchpoints:

    list where data enters the system: forms, apps, APIs, file imports, email, Zalo, hotline.

  2. Map processing flows:

    where data originates, who accesses it, who receives it, where it's stored, when it's deleted.

  3. Classify data:

    distinguish regular data from sensitive data to apply appropriate controls.

  4. Check the legal basis:

    determine whether it is consent, contract, legal obligation, or another basis under the Law.

  5. Review third parties:

    do advertising, cloud, CRM, logistics, payment, or AI tools receive data?

  6. Establish compliance documentation:

    notices, consent capture mechanisms, access controls, logs, DSAR and incident-handling procedures.

Does the Law have extraterritorial effect?

Yes. Under the Law, its scope can extend outside Vietnam if the processing relates to personal data of individuals in Vietnam or affects the processing of that data. This is critical for businesses using international platforms such as cloud, CRM, email marketing, analytics, advertising, AI APIs.

Practical example: a company in Singapore provides an app to Vietnamese users, collects phone numbers and usage behavior, and transfers the data to servers overseas. In this case, PDPL obligations in Vietnam may arise under the Law, even though servers are not located in Vietnam.

Businesses should not assume that “servers abroad means it’s irrelevant.” In practice, the decisive factor is whether you process personal data of people in Vietnam and whether that processing falls within the Law’s scope.

What exceptions might reduce full application?

The Law provides for exceptions or special application mechanisms, but these should not be read as “blanket exemptions.” Typically, exceptions are confined to specific activities such as requests from competent state authorities, national defense and security, investigation and litigation, or emergencies as provided by law.

For businesses, a safe approach is to:

  • Do not assume you are exempt.
  • If processing data in a special context, verify the specific legal basis.
  • For sensitive data or cross-border data transfers, have counsel review before implementation.

What should SMEs do now?

The first step is not to draft a long policy, but to inventory your data and processing flows. If you don’t know where data is, who uses it, and for what, it will be hard to demonstrate compliance.

Top 5 priorities:

  • Review data collection forms on your web/app.
  • Check your cookie banner and the mechanism to store proof of consent.
  • List the third parties that receive data.
  • Standardize the process for responding to data subject requests (DSAR).
  • Set up an incident response process, as data breach notifications must be made within 72 hours of discovery.

If you are building a website or digital product, consent.vn can help you standardize cookie banners, proof-of-consent storage, and DSAR workflows in a pragmatic way.

Potentially yes, if cookies or IPs are used to identify, track, analyze, or link to a specific individual under the Law.
Potentially yes. If the cloud processes personal data of people in Vietnam, you must consider compliance obligations and cross-border transfer requirements under the Law.
Yes. These are basic personal data, and collecting, storing, and using them for marketing or customer care are data processing activities.
No. Exceptions typically apply to specific contexts; businesses should still verify the legal basis and consult counsel if the situation is unclear.

Source: the Personal Data Protection Law (Law 91/2025/QH15); Decree 13/2023/ND-CP — thuvienphapluat.vn. Enforcing authority: Ministry of Public Security/A05 — bocongan.gov.vn.

Get started — no account needed.

Ready to comply with PDPL?

Get started