Article · June 17, 2026
What is the structure of the Personal Data Protection Law: 5 chapters, 39 articles?
Summary of the 5 chapters and 39 articles of Law 91/2025/QH15 to guide businesses in reading the law and preparing PDPL compliance.
Quick answer
What is the structure of the Personal Data Protection Law with 5 chapters and 39 articles?
This structure helps businesses read the law in the right order of priority: understand concepts and principles first, then individuals’ rights, the obligations of processing parties, special situations such as cross-border data transfers, and finally sanctions and enforcement.
If you are an SME or a technical team, the most effective way is not to read it once from start to finish, but to read according to “what you are doing”: collecting customer data, running ads, using SaaS, storing logs, sending email/SMS, or sharing data with partners.
Read Chapter I first:
identify scope, definitions of personal data, and processing principles to know which data your systems touch.
Read Chapter II next:
review user/customer rights to prepare mechanisms for requests such as access, rectification, withdrawal of consent, and deletion of data.
Read Chapter III to map internal obligations:
determine who is the controller, processor, joint controller/processor, and third party; what must be notified, what evidence must be retained, and how to control processing.
Read Chapter IV if you transfer data or process sensitive data:
especially useful for SaaS, fintech, HR, e-commerce, and marketing automation.
Read Chapter V to prepare incident handling and compliance checks:
this is the part businesses often overlook when they only focus on checkbox consent.
What does Chapter I cover and what should businesses watch for?
Chapter I is the foundation: scope of regulation, subjects of application, core concepts, and principles for processing personal data. For businesses, this determines whether you are processing personal data, and whether that processing is purpose-appropriate, based on a valid legal basis, and data-minimised.
A key point is how the law defines and classifies data. In the Vietnamese context, a sign-up form, IP logs, identifier cookies, phone numbers, email addresses, profile photos, and HR records can all bring a business within the scope of the PDPL. Therefore, the product and legal teams should read Chapter I together before designing data collection flows.
How does Chapter II define data subject rights?
Chapter II is what businesses must convert into operating procedures. The core content is individuals’ rights over their data: to be informed, to consent or withdraw consent as prescribed, to access, rectify, erase, restrict processing, object to processing, and other rights under the law.
For businesses, this means having a clear channel for receiving requests. If you use a CRM, CDP, chatbot, contact form, or ticketing system, you need to know who handles customer requests and how quickly you respond. Reading Chapter II helps you avoid the situation of “having a policy but no process”.
What obligations does Chapter III impose on businesses?
Chapter III is core operations: obligations of the data controller, data processor, controller-cum-processor, and third party, along with requirements for safeguards and compliance records. This is the chapter where legal, IT, operations, and procurement should sit together.
Businesses should read this chapter to answer practical questions: who has the right to view customer data; which vendors are processing data on your behalf; whether you have a data processing agreement; whether you log access; whether you have role-based access controls, encryption, backup, and data deletion across the lifecycle. If you use trackers, pixels, or SDKs, the key point is not “is it banned or not”, but that it triggers obligations to notify, manage consent, and control data sharing as required.
What is special in Chapter IV regarding data transfers and sensitive scenarios?
Chapter IV is where businesses need to pay the most attention if they transfer data abroad, process sensitive data, or operate in higher-risk sectors such as finance, healthcare, insurance, HR, and digital platforms. This part directly relates to system architecture, cloud providers, and cross-border data flows.
If your company uses servers in Singapore, an email service in the U.S., or behavior analytics tools provided from overseas, read Chapter IV very carefully. The goal is to identify notification obligations, impact assessments, and documentation required by the regulations. When in doubt, consult a lawyer before implementation rather than auditing after the fact.
What does Chapter V say about enforcement, inspection, and handling violations?
Chapter V is often read last but should be read early to understand real risks. It typically relates to the responsibilities of regulators, inspections, audits, handling violations, and implementation provisions.
The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05). Specific fines will be prescribed by Government implementing decrees; you should not speculate on figures at this time. For serious violations, businesses or related individuals may be subject to criminal liability as provided by law.
In what order should businesses prioritize reading the law?
If the goal is rapid compliance implementation, the recommended order is: Chapter I to define data scope, Chapter II to design user rights, Chapter III to map internal processes, Chapter IV to review vendors and data transfers, and Chapter V to understand sanctions risk and prepare responses.
Practical example: an e-commerce company in Vietnam typically needs to review sign-up forms, the cookie banner, email/SMS marketing, data sharing with carriers, payment gateways, and customer service systems. Each touchpoint will relate to one or more chapters of the law.
| Chapter | Main contents | What businesses should do | |
|---|---|---|---|
| Chapter I | Scope, definitions, principles | Inventory data, identify personal data and legal bases for processing | |
| Chapter II | Data subject rights | Design DSAR, withdrawal of consent, delete/edit/access data | |
| Chapter III | Obligations of the processing parties | Review roles, contracts, access controls, retain evidence | |
| Chapter IV | Special scenarios, data transfers | Check cloud, foreign vendors, sensitive data | |
| Chapter V | Enforcement, inspection, violations | Prepare incident response, reporting and compliance documentation |
- It’s enough to orient how to read the law and form an initial plan, but businesses still need to consult the full text of the law, implementing decrees, and legal counsel for real-world data flows.
- Read Chapter I and Chapter II first, because they help define what data you process and what rights you must satisfy for customers/employees.
- Focus on Chapter III and Chapter IV to check contractual obligations, third-party controls, and requirements related to cross-border data transfers as prescribed.
- The Personal Data Protection Law (Law 91/2025/QH15) takes effect on 01/01/2026. The enforcement authority is the Ministry of Public Security (A05).
If you need to map a cookie banner, store consent evidence, or align DSAR workflows with your systems, consent.vn can help ops and dev teams implement correctly from the start.
Source: the Personal Data Protection Law (Law 91/2025/QH15): https://thuvienphapluat.vn ; Decree 13/2023/ND-CP: https://thuvienphapluat.vn ; Ministry of Public Security/A05: https://bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?