Article · June 17, 2026

What is basic personal data? How it differs from sensitive data

Explains what basic personal data includes, examples, and how to distinguish it from sensitive data under the PDPL for Vietnamese businesses.

consent.vn Editorial6 min read

Quick answer

Basic personal data are information used to identify or contact an individual, such as full name, date of birth, email, phone number, personal identification number, address, portrait photo, identification account, and some data generated from the use of services. Correctly distinguishing this from sensitive data helps businesses apply appropriate protection obligations under the Personal Data Protection Law.

What does basic personal data include?

Basic personal data are a set of information directly linked to a person and commonly used to identify, contact, reconcile records, or operate a service. For Vietnamese businesses, this group often appears in sign-up forms, CRMs, apps, landing pages, e-invoices, and customer support systems.

Common examples include:

  • Full name
  • Date of birth
  • Gender
  • Phone number
  • Email
  • Permanent/temporary address, shipping address
  • Personal identification number/CCCD/passport number
  • Portrait photo, photos of identity documents if used for identification
  • User account, username, customer ID, membership ID
  • Location data or device logs if they can be linked to a specific individual under the rules

Key point to remember: not all “technical data” are harmless. If a device ID, cookie ID, IP log, or customer ID can be used to identify a specific person in your system, it may be considered personal data under the rules.

How to distinguish basic personal data from sensitive data?

The most practical way is to ask: does this information only help identify/contact, or, if exposed, could it cause more serious impacts on the person’s privacy, finances, reputation, health, or safety?

CriteriaBasic personal dataSensitive personal data
Primary purposeIdentification, contact, record managementCan more deeply affect the individual's rights and interests
ExamplesFull name, email, phone number, date of birth, addressHealth data, biometric data, religion, political opinions, sexual life, financial data, detailed location data, children's data in certain cases as provided by law
Risk levelTypically lowerHigher, requires tighter controls
Processing obligationsStill requires a valid legal basis, transparent notices, and securityTypically requires stricter legal grounds and safeguards, as provided by law

Real-world examples:

  • Email used to send invoices: basic data.
  • Phone number used to verify orders: basic data.
  • Gym customers’ medical exam results: sensitive data.
  • Citizen ID (CCCD) images used for KYC to open an account: the identifying information is personal data; if you also collect health, religion, or biometric information, the protection obligations increase.

What should businesses do when collecting these data?

If you collect names, emails, phone numbers, or identification numbers, you are not merely “storing customer info” — you are processing personal data. Under the rules, businesses need to define the purpose, data types, retention period, data recipients, and safeguards right from the system design stage.

  1. List every data field:

    review forms, apps, CRM, chatbots, Excel files, and APIs to know what you collect.

  2. Attach a processing purpose to each field:

    e.g., email to send transaction notices, phone number for OTP verification, date of birth to verify age.

  3. Separate basic and sensitive data:

    if a form asks for health, biometric, or bank account information, flag it and apply tighter procedures.

  4. Update your privacy notice:

    state who processes, why, with whom it's shared, how long it's kept, and how users can request access/deletion/update.

  5. Limit internal access rights:

    if customer service doesn’t need to see a full CCCD scan, they shouldn’t have that permission.

  6. Keep evidence and logs:

    record consent, policy changes, and access logs to be ready for audits and incidents.

  7. Prepare an incident process:

    if a breach occurs, rapidly assess impact, contain it, and give a data breach notice within 72 hours from discovery as required.

What are examples of basic personal data in Vietnamese businesses?

Typical SME examples:

  • An online shop collects full name, phone number, shipping address to deliver orders
  • A training center collects date of birth, email, phone number to manage classes and send notifications
  • SaaS/B2B collects name, job title, company email, phone number to create accounts and provide technical support
  • A bank/fintech collects personal identification numbers, CCCD images, email, phone number for KYC and reconciliation

If your business uses cookies, pixels, SDKs, or trackers to measure user behavior, do not assume this is “just for marketing.” Under the rules, you must determine whether you are collecting personal data, whether you share it with third parties, and whether you have provided appropriate notice/obtained consent.

Which authority enforces and what are the penalties?

The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05). Specific fines will be set by the Government’s implementing decree; the law currently does not fix amounts. For serious violations, the business or related individuals may be subject to criminal liability as provided by law.

The important thing is not to wait for an inspection to classify data. As soon as you collect emails, phone numbers, identification numbers, or images of identity documents, your system needs a clear policy and at least minimal handling procedures.

Typically includes full name, date of birth, email, phone number, address, personal identification number, portrait photo, user account, and information used to identify or contact a person.
Not by default. They are usually basic personal data. However, how you use, combine, or share them must still comply with personal data protection rules.
The identifying information in a CCCD is typically personal data; if you also collect biometric, financial, or other categories considered sensitive, the protection obligations will be higher.
Yes. You still need to notify purposes of processing, restrict access, store securely, and have a process to handle data subject requests as required.

If you are reviewing sign-up forms, cookie banners, or consent evidence workflows, consent.vn can help quickly standardize them under the PDPL, especially for the practical needs of SMEs and dev teams.

Source: the Personal Data Protection Law (Law 91/2025/QH15), see at thuvienphapluat.vn; Decree 13/2023/ND-CP, see at thuvienphapluat.vn; enforcement authority the Ministry of Public Security/A05, see at bocongan.gov.vn

Get started — no account needed.

Ready to comply with PDPL?

Get started