The Law on Personal Data Protection No. 91/2025/QH15 will take effect from January 1, 2026.

A) SUMMARY OF THIS LAW:
Chapter I – General Provisions
Main contents:
  • Defines scope of regulation and subjects of application.
  • Provides definitions of key terms: personal data, basic data, sensitive data, data processing, data controller, data processor, de-identification, etc.
  • Principles of personal data protection: purpose limitation, accuracy, security, non‑infringement of personal rights.
  • Rights and obligations of data subjects: right to be informed, to consent, to correct, to request deletion, to complain, etc.
  • Prohibited acts: buying/selling data, data appropriation, unlawful processing, etc.
  • Violations may be penalized up to 3 billion VND or 5% of revenue for cross‑border violations.
Chapter II – Protection of Personal Data
Section 1 – During Personal Data Processing
Main contents:
  • Consent requirements: must be explicit, specific, unambiguous; silence does not constitute consent.
  • Right to withdraw consent and request processing restrictions.
  • Collection, analysis, and aggregation of data require consent (except where permitted by law).
  • Rules on encryption/decryption, data modification, deletion, destruction, and de‑identification.
  • Providing data to the data subject or third parties when consent is granted.
  • Public disclosure must align with the stated purpose and must not infringe personal rights.
  • Data transfer within an organization, during mergers/acquisitions, upon request of authorities, or with the data subject’s consent.

Chapter III – Processing Personal Data Without Consent
Main contents:
  • Special cases where data may be processed without consent, such as:
  • Protecting life and health in emergencies.
  • Crime prevention and counter‑terrorism.
  • Serving state management functions.
  • Fulfilling contractual obligations.
  • Responsibilities of entities when processing without consent.
Chapter IV – Cross‑Border Transfer of Personal Data
Main contents:
  • Conditions for transferring personal data abroad.
  • Requirement to conduct a Data Transfer Impact Assessment and submit it to the Ministry of Public Security within 60 days.
  • Cases exempted from impact assessment.
  • Right to request suspension of data transfer if it threatens national security.
  • Responsibilities of foreign data recipients.
Chapter V – Personal Data Protection in Specific Sectors
Main contents:
  • Special regulations for:
  • Children and persons lacking legal capacity.
  • Recruitment and labor management.
  • Healthcare and insurance.
  • Finance, banking, and credit.
  • Advertising and marketing.
  • Social networks and digital platforms.
  • Location data and biometric data.
  • Audio/video recording in public places.
  • Emerging technologies: AI, blockchain, cloud computing, metaverse, etc.
Chapter VI – Personal Data Protection Forces
Main contents:
  • Identifies the core authority: the Ministry of Public Security.
  • Requirements for internal data protection units within organizations.
  • Regulations on organizations providing data protection services.
  • Coordination mechanisms among relevant agencies.
Chapter VII – Implementation Provisions
Main contents:
  • Effective date: January 1, 2026.
  • Transitional provisions: small businesses and startups are exempt from certain obligations for 5 years.
  • Impact assessment dossiers under Decree 13/2023 remain valid


B) RISK & IMPACT ANALYSIS OF VIETNAM’S PERSONAL DATA PROTECTION LAW 2025

The Personal Data Protection Law 91/2025/QH15 marks a major regulatory shift in Vietnam, comparable to the GDPR in Europe. It establishes a strong legal framework for personal data protection while imposing significant obligations on organizations that process data.

Below is a three‑layer analysis: legal risks, operational risks, and strategic impacts.

I. LEGAL RISKS
1. High administrative penalties
The law sets substantial maximum fines:
  • Up to 3 billion VND for most violations.
  • 10 times the revenue gained from illegal data trading.
  • 5% of the previous year’s revenue for cross‑border data transfer violations.

These penalties align with international standards and pose major risks for digital‑driven businesses.

2. Criminal liability
Certain actions may lead to criminal prosecution, including:
  • Data appropriation.
  • Intentional disclosure or destruction of data.
  • Using personal data to commit unlawful acts.

This creates heightened exposure for IT, marketing, and data operations personnel.

3. Risks related to “explicit consent”
The law requires:
  • Consent must be explicit, specific, and not pre‑ticked or defaulted.
  • Multiple purposes cannot be bundled into a single consent request.
  • Silence does not constitute consent.

This invalidates many legacy “default‑on” data collection models.

4. Risks from data deletion obligations

Data subjects may request deletion or restriction of processing. Organizations must comply within statutory deadlines. If systems cannot fully delete or erase data → non‑compliance.

5. Risks in processing sensitive data

Sensitive data (health, biometrics, location, finance, etc.) requires enhanced protection. Industries facing the highest exposure: Healthcare, Banking, Insurance, E‑commerce, Fintech, Telecommunications

6. Risks in cross‑border data transfers
The law requires:
  • A Data Transfer Impact Assessment.
  • Submission to the Ministry of Public Security within 60 days.
  • Transfers may be suspended if they pose national security risks.
  • Companies using international cloud services (AWS, Google Cloud, Meta, TikTok, etc.) will be heavily affected.
II. OPERATIONAL RISKS
1. IT systems may fail to meet compliance requirements
The law mandates:
  • Data encryption.
  • De‑identification.
  • Access control.
  • Monitoring of public data disclosures.
  • Secure deletion/destruction.
  • Legacy systems may not support these capabilities.
2. Human‑related risks
Employees may:
  • Copy data externally.
  • Share data via personal email.
  • Store data on personal devices.
  • Use customer data for marketing without proper consent.
The law requires strict training and internal controls.
3. Third‑party risks
Vendors such as:
  • CRM providers
  • Email marketing platforms
  • Cloud services
  • Data analytics firms
  • Call centers
  • Advertising agencies

If they violate the law → the organization remains liable.

4. Risks from unstandardized internal processes
Examples:
– No process for handling data deletion requests.
– No incident reporting workflow for data breaches.

– No impact assessment when launching new products or features.

III. STRATEGIC IMPACTS
1. Positive impacts
a. Increased customer trust
Organizations with strong compliance will Enhance reputation, Improve international competitiveness and Attract privacy‑conscious customers.
b. Alignment with global standards
The law is compatible with:
  • GDPR (EU)
  • PDPA (Singapore)
  • CCPA (California)
This facilitates international expansion.
c. Boost to cybersecurity investment
Creates demand for:
  • SOC
  • SIEM
  • DLP
  • IAM
  • Zero Trust architectures
  • Cloud security solutions
2. Negative impacts / challenges
a. Significant compliance costs
Including:
  • Technical systems
  • Data protection personnel
  • Impact assessments
  • Legal consulting
  • Third‑party monitoring
b. Disruption to data‑driven business models
Industries most affected:
  • Digital advertising
  • User behavior analytics
  • Data brokerage
  • Fintech using alternative data
  • Social media platforms
c. Operational disruption risks
Organizations may be required to:
  • Stop processing certain data.
  • Suspend cross‑border data transfers.
This can lead to system downtime or business interruption.