Article · June 17, 2026
Who Must Comply with the Personal Data Protection Law?
Who must comply with Vietnam's Personal Data Protection Law? Key notes for orgs and businesses in or outside Vietnam processing Vietnamese data.
Quick answer
Who must comply with the personal data protection law?
Short answer: anyone involved in collecting, storing, analyzing, sharing, transferring, or deleting personal data of Vietnamese individuals may incur compliance obligations under the Personal Data Protection Law.
In practice, the groups that should pay the most attention include:
- Vietnamese businesses with websites/apps, CRM, marketing systems, HR, cameras, call centers, eKYC.
- Foreign businesses that provide services to users in Vietnam or process Vietnamese data remotely.
- Technology service providers: cloud, SaaS, adtech, analytics, email/SMS/OTP, chatbot, CDP.
- Outsourced processors: call centers, payroll, recruitment, logistics, marketplace operations.
- Individuals or household businesses that collect data from customers, employees, or partners.
The Personal Data Protection Law (Law 91/2025/QH15) was passed on 26/06/2025 and takes effect from 01/01/2026. This law replaces/upgrades the framework in Decree 13/2023/ND-CP, so businesses using Decree 13 as the baseline should review to prepare for the new phase.
Do domestic businesses have to comply?
Yes. If your business in Vietnam processes data of customers, candidates, employees, or partners, you are almost certainly within scope.
Very common examples:
- An online shop stores phone numbers, addresses, purchase history.
- A recruitment firm stores CVs, citizen ID, diplomas of candidates.
- HR stores salary records, social insurance, timekeeping.
- A CRM stores call notes, behavior tags, and transaction history.
In these cases, businesses need more than just “a privacy policy” — they also need a governance foundation: clear processing purposes, appropriate legal bases, data minimization, access controls, storing consent evidence where needed, and mechanisms to handle data subject requests.
Do foreign businesses have to comply?
Possibly. If a business outside Vietnam processes the personal data of Vietnamese individuals, the law may still apply under the regulations.
This commonly arises in:
- E-commerce platforms with users in Vietnam.
- SaaS applications with Vietnamese customers.
- Ad networks, user behavior measurement, cross-platform tracking.
- Providers of booking, airline ticketing, transportation, e-wallets, and games.
Important point: simply “hosting servers abroad” does not avoid obligations. If you collect or determine the purposes for processing Vietnamese data, you may have to meet requirements such as notice, consent, processing agreements, third-party management, and internal records as prescribed.
Do individuals have to comply?
Yes, if an individual processes data not purely for personal or family life but linked to professional or business activities, or in an organized, repeated, or significant-scale manner.
Examples:
- Freelancers keeping customer lists, phone numbers, emails, payment history.
- KOLs/creators running their own landing pages, sign-up forms, lead lists.
- Owners of classes, gyms, spas, clinics storing customer records.
- Individuals providing recruitment, customer care, or brokerage services.
In short: “acting as an individual” does not mean “not applicable.” If you collect data to serve clearly defined activities, you should treat yourself as having compliance obligations.
| Group | May have to comply? | Typical obligations | |
|---|---|---|---|
| Vietnamese businesses | Yes | Notice, consent, access control, security, DSAR | |
| Foreign businesses | Yes | Comply per regulations when processing Vietnamese data | |
| Sole proprietors/freelancers | Possibly | Process only for stated purposes, limit sharing, keep evidence | |
| Outsourced processors | Yes | Data processing agreements, security, process only as instructed |
When does an entity incur compliance obligations?
You should consider yourself “subject to compliance” when you have at least one of the following situations:
- Collect personal data via forms, apps, cookies, CRM, hotlines, POS.
- Store or back up customer, employee, or candidate data.
- Analyze/profile user behavior for marketing, scoring, or recommendations.
- Share with third parties such as delivery, payment, or advertising partners.
- Transfer data overseas or use infrastructure outside Vietnam.
- Process sensitive data such as citizen ID, biometrics, health, or financial data.
Identify what types of data you process:
list customer, employee, candidate, and partner data; flag sensitive data.
Determine your role:
controller, processor, or joint controller; for each data flow, record who decides the purposes and means.
Review collection points:
web forms, apps, cookies, APIs, POS, contracts, offline; check that notice and legal bases are in place.
Standardize documentation:
privacy notice, consent log, DPA/processing agreements, DSAR workflow, incident handling procedure.
Implement technical controls:
access control, encryption, logging, retention, backup, lifecycle deletion.
Prepare for incidents:
designate a point of contact, keep an internal playbook, and have a data breach notification process within 72 hours of discovery.
If there is a violation, who is sanctioned?
Depending on the act and severity, the involved organization or individual may be sanctioned under the Government’s guiding decree; serious violations may be handled criminally. The enforcement authority is the Ministry of Public Security, specifically the Department of Cybersecurity and High-Tech Crime Prevention (A05).
Because specific fines are set by the guiding decree and amounts are not yet fixed, businesses should not wait for a “penalty table” before acting. In practice, risks often come from very everyday mistakes: using lead forms without notice, sharing data with partners without a processing agreement, or lacking a response process when data leaks.
What should SMEs do now?
If you are an SME, start with high-impact, quick wins:
- Inventory the personal data you hold.
- Record clear processing purposes for each data flow.
- Review consent, cookie banners, checkboxes, email marketing.
- Check contracts with vendors, agencies, cloud, call centers.
- Set up processes to handle access/erasure/rectification requests.
- Prepare an incident playbook so you are not caught flat-footed in a breach.
If you need to systematize this for your website, app, or CRM, consent.vn can help you manage cookie banners, store consent evidence, and DSAR flows in an easier-to-deploy way.
- Organizations, individuals, and businesses inside and outside Vietnam that process the personal data of Vietnamese individuals may have to comply under the regulations.
- Possibly, if that company processes the personal data of Vietnamese individuals or provides services to users in Vietnam under the regulations.
- Possibly, if the freelancer collects and processes customer data for professional or business activities, not just for personal or household purposes.
- Under the regulations, data breach notification must be made within 72 hours of discovery.
Source: the Personal Data Protection Law (Law 91/2025/QH15) on thuvienphapluat.vn; Decree 13/2023/ND-CP on thuvienphapluat.vn; Ministry of Public Security/A05 on bocongan.gov.vn
Get started — no account needed.
Ready to comply with PDPL?