{"id":1586,"date":"2026-01-01T08:03:26","date_gmt":"2026-01-01T08:03:26","guid":{"rendered":"https:\/\/lawpage.vn\/?p=1586"},"modified":"2026-08-01T14:08:39","modified_gmt":"2026-08-01T14:08:39","slug":"the-law-on-personal-data-protection-no-91-2025-qh15-will-take-effect-from-january-1-2026","status":"publish","type":"post","link":"https:\/\/lawpage.vn\/en\/the-law-on-personal-data-protection-no-91-2025-qh15-will-take-effect-from-january-1-2026\/","title":{"rendered":"The Law on Personal Data Protection No. 91\/2025\/QH15 will take effect from January 1, 2026."},"content":{"rendered":"<div style=\"text-align: justify\"><span style=\"color: #000080\"><strong>A) SUMMARY OF THIS LAW:<\/strong><\/span><\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>Chapter I \u2013 General Provisions<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Defines scope of regulation and subjects of application.<\/li>\n<li>Provides definitions of key terms: personal data, basic data, sensitive data, data processing, data controller, data processor, de-identification, etc.<\/li>\n<li>Principles of personal data protection: purpose limitation, accuracy, security, non\u2011infringement of personal rights.<\/li>\n<li>Rights and obligations of data subjects: right to be informed, to consent, to correct, to request deletion, to complain, etc.<\/li>\n<li>Prohibited acts: buying\/selling data, data appropriation, unlawful processing, etc.<\/li>\n<li>Violations may be penalized up to 3 billion VND or 5% of revenue for cross\u2011border violations.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>Chapter II \u2013 Protection of Personal Data<\/strong><\/div>\n<div style=\"text-align: justify\">Section 1 \u2013 During Personal Data Processing<\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Consent requirements: must be explicit, specific, unambiguous; silence does not constitute consent.<\/li>\n<li>Right to withdraw consent and request processing restrictions.<\/li>\n<li>Collection, analysis, and aggregation of data require consent (except where permitted by law).<\/li>\n<li>Rules on encryption\/decryption, data modification, deletion, destruction, and de\u2011identification.<\/li>\n<li>Providing data to the data subject or third parties when consent is granted.<\/li>\n<li>Public disclosure must align with the stated purpose and must not infringe personal rights.<\/li>\n<li>Data transfer within an organization, during mergers\/acquisitions, upon request of authorities, or with the data subject\u2019s consent.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><strong><br \/>\nChapter III \u2013 Processing Personal Data Without Consent<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Special cases where data may be processed without consent, such as:<\/li>\n<li>Protecting life and health in emergencies.<\/li>\n<li>Crime prevention and counter\u2011terrorism.<\/li>\n<li>Serving state management functions.<\/li>\n<li>Fulfilling contractual obligations.<\/li>\n<li>Responsibilities of entities when processing without consent.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><strong>Chapter IV \u2013 Cross\u2011Border Transfer of Personal Data<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Conditions for transferring personal data abroad.<\/li>\n<li>Requirement to conduct a Data Transfer Impact Assessment and submit it to the Ministry of Public Security within 60 days.<\/li>\n<li>Cases exempted from impact assessment.<\/li>\n<li>Right to request suspension of data transfer if it threatens national security.<\/li>\n<li>Responsibilities of foreign data recipients.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>Chapter V \u2013 Personal Data Protection in Specific Sectors<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Special regulations for:<\/li>\n<li>Children and persons lacking legal capacity.<\/li>\n<li>Recruitment and labor management.<\/li>\n<li>Healthcare and insurance.<\/li>\n<li>Finance, banking, and credit.<\/li>\n<li>Advertising and marketing.<\/li>\n<li>Social networks and digital platforms.<\/li>\n<li>Location data and biometric data.<\/li>\n<li>Audio\/video recording in public places.<\/li>\n<li>Emerging technologies: AI, blockchain, cloud computing, metaverse, etc.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>Chapter VI \u2013 Personal Data Protection Forces<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Identifies the core authority: the Ministry of Public Security.<\/li>\n<li>Requirements for internal data protection units within organizations.<\/li>\n<li>Regulations on organizations providing data protection services.<\/li>\n<li>Coordination mechanisms among relevant agencies.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>Chapter VII \u2013 Implementation Provisions<\/strong><\/div>\n<div style=\"text-align: justify\">Main contents:<\/div>\n<ul style=\"list-style-type: circle;text-align: justify\">\n<li>Effective date: January 1, 2026.<\/li>\n<li>Transitional provisions: small businesses and startups are exempt from certain obligations for 5 years.<\/li>\n<li>Impact assessment dossiers under Decree 13\/2023 remain valid<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><span style=\"color: #000080\"><strong><br \/>\nB) RISK &amp; IMPACT ANALYSIS OF VIETNAM\u2019S PERSONAL DATA PROTECTION LAW 2025<\/strong><\/span><\/p>\n<div style=\"text-align: justify\">The Personal Data Protection Law 91\/2025\/QH15 marks a major regulatory shift in Vietnam, comparable to the GDPR in Europe. It establishes a strong legal framework for personal data protection while imposing significant obligations on organizations that process data.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">\n<p>Below is a three\u2011layer analysis: legal risks, operational risks, and strategic impacts.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>I. LEGAL RISKS<\/strong><\/div>\n<div style=\"text-align: justify\">1. High administrative penalties<\/div>\n<div style=\"text-align: justify\">The law sets substantial maximum fines:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Up to 3 billion VND for most violations.<\/li>\n<li style=\"text-align: justify\">10 times the revenue gained from illegal data trading.<\/li>\n<li style=\"text-align: justify\">5% of the previous year\u2019s revenue for cross\u2011border data transfer violations.<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>These penalties align with international standards and pose major risks for digital\u2011driven businesses.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">2. Criminal liability<\/div>\n<div style=\"text-align: justify\">Certain actions may lead to criminal prosecution, including:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Data appropriation.<\/li>\n<li style=\"text-align: justify\">Intentional disclosure or destruction of data.<\/li>\n<li style=\"text-align: justify\">Using personal data to commit unlawful acts.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">\n<p>This creates heightened exposure for IT, marketing, and data operations personnel.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">3. Risks related to \u201cexplicit consent\u201d<\/div>\n<div style=\"text-align: justify\">The law requires:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Consent must be explicit, specific, and not pre\u2011ticked or defaulted.<\/li>\n<li style=\"text-align: justify\">Multiple purposes cannot be bundled into a single consent request.<\/li>\n<li style=\"text-align: justify\">Silence does not constitute consent.<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>This invalidates many legacy \u201cdefault\u2011on\u201d data collection models.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">4. Risks from data deletion obligations<\/div>\n<div style=\"text-align: justify\">\n<p>Data subjects may request deletion or restriction of processing. Organizations must comply within statutory deadlines. If systems cannot fully delete or erase data \u2192 non\u2011compliance.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">5. Risks in processing sensitive data<\/div>\n<div style=\"text-align: justify\">\n<p>Sensitive data (health, biometrics, location, finance, etc.) requires enhanced protection. Industries facing the highest exposure: Healthcare, Banking, Insurance, E\u2011commerce, Fintech, Telecommunications<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">6. Risks in cross\u2011border data transfers<\/div>\n<div style=\"text-align: justify\">The law requires:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">A Data Transfer Impact Assessment.<\/li>\n<li style=\"text-align: justify\">Submission to the Ministry of Public Security within 60 days.<\/li>\n<li style=\"text-align: justify\">Transfers may be suspended if they pose national security risks.<\/li>\n<li style=\"text-align: justify\">Companies using international cloud services (AWS, Google Cloud, Meta, TikTok, etc.) will be heavily affected.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><strong>II. OPERATIONAL RISKS<\/strong><\/div>\n<div style=\"text-align: justify\">1. IT systems may fail to meet compliance requirements<\/div>\n<div style=\"text-align: justify\">The law mandates:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Data encryption.<\/li>\n<li style=\"text-align: justify\">De\u2011identification.<\/li>\n<li style=\"text-align: justify\">Access control.<\/li>\n<li style=\"text-align: justify\">Monitoring of public data disclosures.<\/li>\n<li style=\"text-align: justify\">Secure deletion\/destruction.<\/li>\n<li style=\"text-align: justify\">Legacy systems may not support these capabilities.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">2. Human\u2011related risks<\/div>\n<div style=\"text-align: justify\">Employees may:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Copy data externally.<\/li>\n<li style=\"text-align: justify\">Share data via personal email.<\/li>\n<li style=\"text-align: justify\">Store data on personal devices.<\/li>\n<li style=\"text-align: justify\">Use customer data for marketing without proper consent.<\/li>\n<\/ul>\n<div style=\"text-align: justify\">The law requires strict training and internal controls.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">3. Third\u2011party risks<\/div>\n<div style=\"text-align: justify\">Vendors such as:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">CRM providers<\/li>\n<li style=\"text-align: justify\">Email marketing platforms<\/li>\n<li style=\"text-align: justify\">Cloud services<\/li>\n<li style=\"text-align: justify\">Data analytics firms<\/li>\n<li style=\"text-align: justify\">Call centers<\/li>\n<li style=\"text-align: justify\">Advertising agencies<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>If they violate the law \u2192 the organization remains liable.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">4. Risks from unstandardized internal processes<\/div>\n<div style=\"text-align: justify\">Examples:<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">&#8211; No process for handling data deletion requests.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">&#8211; No incident reporting workflow for data breaches.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">\n<p>&#8211; No impact assessment when launching new products or features.<\/p>\n<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\"><strong>III. STRATEGIC IMPACTS<\/strong><\/div>\n<div style=\"text-align: justify\">1. Positive impacts<\/div>\n<div style=\"text-align: justify\">a. Increased customer trust<\/div>\n<div style=\"text-align: justify\">Organizations with strong compliance will Enhance reputation, Improve international competitiveness and Attract privacy\u2011conscious customers.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">b. Alignment with global standards<\/div>\n<div style=\"text-align: justify\">The law is compatible with:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">GDPR (EU)<\/li>\n<li style=\"text-align: justify\">PDPA (Singapore)<\/li>\n<li style=\"text-align: justify\">CCPA (California)<\/li>\n<\/ul>\n<div style=\"text-align: justify\">This facilitates international expansion.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">c. Boost to cybersecurity investment<\/div>\n<div style=\"text-align: justify\">Creates demand for:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">SOC<\/li>\n<li style=\"text-align: justify\">SIEM<\/li>\n<li style=\"text-align: justify\">DLP<\/li>\n<li style=\"text-align: justify\">IAM<\/li>\n<li style=\"text-align: justify\">Zero Trust architectures<\/li>\n<li style=\"text-align: justify\">Cloud security solutions<\/li>\n<\/ul>\n<div style=\"text-align: justify\">2. Negative impacts \/ challenges<\/div>\n<div style=\"text-align: justify\">a. Significant compliance costs<\/div>\n<div style=\"text-align: justify\">Including:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Technical systems<\/li>\n<li style=\"text-align: justify\">Data protection personnel<\/li>\n<li style=\"text-align: justify\">Impact assessments<\/li>\n<li style=\"text-align: justify\">Legal consulting<\/li>\n<li style=\"text-align: justify\">Third\u2011party monitoring<\/li>\n<\/ul>\n<div style=\"text-align: justify\">b. Disruption to data\u2011driven business models<\/div>\n<div style=\"text-align: justify\">Industries most affected:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Digital advertising<\/li>\n<li style=\"text-align: justify\">User behavior analytics<\/li>\n<li style=\"text-align: justify\">Data brokerage<\/li>\n<li style=\"text-align: justify\">Fintech using alternative data<\/li>\n<li style=\"text-align: justify\">Social media platforms<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">c. Operational disruption risks<\/div>\n<div style=\"text-align: justify\">Organizations may be required to:<\/div>\n<ul style=\"list-style-type: circle\">\n<li style=\"text-align: justify\">Stop processing certain data.<\/li>\n<li style=\"text-align: justify\">Suspend cross\u2011border data transfers.<\/li>\n<\/ul>\n<div style=\"text-align: justify\"><\/div>\n<div style=\"text-align: justify\">This can lead to system downtime or business interruption.<\/div>\n<div style=\"text-align: justify\"><\/div>\n<p style=\"text-align: justify\">\n","protected":false},"excerpt":{"rendered":"<p>A) SUMMARY OF THIS LAW: Chapter I \u2013 General Provisions Main contents: Defines scope of regulation and subjects of application. Provides definitions of key terms: personal data, basic data, sensitive data, data processing, data controller, data processor, de-identification, etc. Principles of personal data protection: purpose limitation, accuracy, security, non\u2011infringement of personal rights. Rights and obligations [&#8230;]\n","protected":false},"author":78,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-1586","post","type-post","status-publish","format-standard","hentry","category-legal-updates"],"_links":{"self":[{"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/posts\/1586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/users\/78"}],"replies":[{"embeddable":true,"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/comments?post=1586"}],"version-history":[{"count":0,"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/posts\/1586\/revisions"}],"wp:attachment":[{"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/media?parent=1586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/categories?post=1586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawpage.vn\/en\/wp-json\/wp\/v2\/tags?post=1586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}