- Defines scope of regulation and subjects of application.
- Provides definitions of key terms: personal data, basic data, sensitive data, data processing, data controller, data processor, de-identification, etc.
- Principles of personal data protection: purpose limitation, accuracy, security, non‑infringement of personal rights.
- Rights and obligations of data subjects: right to be informed, to consent, to correct, to request deletion, to complain, etc.
- Prohibited acts: buying/selling data, data appropriation, unlawful processing, etc.
- Violations may be penalized up to 3 billion VND or 5% of revenue for cross‑border violations.
- Consent requirements: must be explicit, specific, unambiguous; silence does not constitute consent.
- Right to withdraw consent and request processing restrictions.
- Collection, analysis, and aggregation of data require consent (except where permitted by law).
- Rules on encryption/decryption, data modification, deletion, destruction, and de‑identification.
- Providing data to the data subject or third parties when consent is granted.
- Public disclosure must align with the stated purpose and must not infringe personal rights.
- Data transfer within an organization, during mergers/acquisitions, upon request of authorities, or with the data subject’s consent.
Chapter III – Processing Personal Data Without Consent
- Special cases where data may be processed without consent, such as:
- Protecting life and health in emergencies.
- Crime prevention and counter‑terrorism.
- Serving state management functions.
- Fulfilling contractual obligations.
- Responsibilities of entities when processing without consent.
- Conditions for transferring personal data abroad.
- Requirement to conduct a Data Transfer Impact Assessment and submit it to the Ministry of Public Security within 60 days.
- Cases exempted from impact assessment.
- Right to request suspension of data transfer if it threatens national security.
- Responsibilities of foreign data recipients.
- Special regulations for:
- Children and persons lacking legal capacity.
- Recruitment and labor management.
- Healthcare and insurance.
- Finance, banking, and credit.
- Advertising and marketing.
- Social networks and digital platforms.
- Location data and biometric data.
- Audio/video recording in public places.
- Emerging technologies: AI, blockchain, cloud computing, metaverse, etc.
- Identifies the core authority: the Ministry of Public Security.
- Requirements for internal data protection units within organizations.
- Regulations on organizations providing data protection services.
- Coordination mechanisms among relevant agencies.
- Effective date: January 1, 2026.
- Transitional provisions: small businesses and startups are exempt from certain obligations for 5 years.
- Impact assessment dossiers under Decree 13/2023 remain valid
B) RISK & IMPACT ANALYSIS OF VIETNAM’S PERSONAL DATA PROTECTION LAW 2025
Below is a three‑layer analysis: legal risks, operational risks, and strategic impacts.
- Up to 3 billion VND for most violations.
- 10 times the revenue gained from illegal data trading.
- 5% of the previous year’s revenue for cross‑border data transfer violations.
These penalties align with international standards and pose major risks for digital‑driven businesses.
- Data appropriation.
- Intentional disclosure or destruction of data.
- Using personal data to commit unlawful acts.
This creates heightened exposure for IT, marketing, and data operations personnel.
- Consent must be explicit, specific, and not pre‑ticked or defaulted.
- Multiple purposes cannot be bundled into a single consent request.
- Silence does not constitute consent.
This invalidates many legacy “default‑on” data collection models.
Data subjects may request deletion or restriction of processing. Organizations must comply within statutory deadlines. If systems cannot fully delete or erase data → non‑compliance.
Sensitive data (health, biometrics, location, finance, etc.) requires enhanced protection. Industries facing the highest exposure: Healthcare, Banking, Insurance, E‑commerce, Fintech, Telecommunications
- A Data Transfer Impact Assessment.
- Submission to the Ministry of Public Security within 60 days.
- Transfers may be suspended if they pose national security risks.
- Companies using international cloud services (AWS, Google Cloud, Meta, TikTok, etc.) will be heavily affected.
- Data encryption.
- De‑identification.
- Access control.
- Monitoring of public data disclosures.
- Secure deletion/destruction.
- Legacy systems may not support these capabilities.
- Copy data externally.
- Share data via personal email.
- Store data on personal devices.
- Use customer data for marketing without proper consent.
- CRM providers
- Email marketing platforms
- Cloud services
- Data analytics firms
- Call centers
- Advertising agencies
If they violate the law → the organization remains liable.
– No impact assessment when launching new products or features.
- GDPR (EU)
- PDPA (Singapore)
- CCPA (California)
- SOC
- SIEM
- DLP
- IAM
- Zero Trust architectures
- Cloud security solutions
- Technical systems
- Data protection personnel
- Impact assessments
- Legal consulting
- Third‑party monitoring
- Digital advertising
- User behavior analytics
- Data brokerage
- Fintech using alternative data
- Social media platforms
- Stop processing certain data.
- Suspend cross‑border data transfers.