Data, Technology & Compliance

Sensitive Personal Data Processing in Vietnam

越南敏感个人数据处理

Sensitive data sits at the highest risk tier in personal data law — when infringed, harm to data subjects is direct and hard to remedy. Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026) defines sensitive personal data at Clause 3 Article 2; the catalogue at Article 4 of Decree 356/2025/ND-CP expands significantly over Decree 13/2023. Processing sensitive data excludes companies from deferral of impact assessment obligations (Clauses 2–3 Article 38).

What is sensitive personal data

Clause 3 Article 2 defines sensitive personal data as personal data attached to individual privacy, whose infringement directly affects lawful rights and interests — in a catalogue issued by the Government. Article 4 of Decree 356/2025/ND-CP lists: racial, ethnic origin; political, religious, belief views; private life, personal and family secrets; health; biometric, genetic characteristics; sexual life, sexual orientation; crime and legal violation data collected and stored by law enforcement agencies; location via positioning services; login credentials, passwords of electronic identification accounts, ID card images; bank accounts, financial transaction history, credit, securities, insurance; and online behavioural tracking data.

Compared to Decree 13/2023, the new catalogue expands in three points: first, legal violation data generally (previously only crimes reaching criminal prosecution); second, financial data extended to securities and insurance; third, online behavioural tracking data — directly affecting digital platforms and behavioural advertising businesses.

Why sensitive data requires higher protection

Sensitive data is attached to privacy, and its infringement directly affects lawful rights and interests. A leaked email is a nuisance; but leaked biometric data cannot be “changed” like a password — faces and fingerprints are unique and permanent. Disclosed health information, sexual life, political or religious views can harm honour and dignity.

The law reflects this risk through two main mechanisms: first, sector-specific regulations (Articles 24–32) largely revolve around sensitive data; second, processing sensitive data excludes companies from deferral or exemption of impact assessment and data protection personnel designation obligations (Article 38).

General principles when processing sensitive data

All Article 3 principles apply to sensitive data, but more strictly: collection limitation — collect only when truly necessary; clear purpose — must be specifically defined, no vague purposes justifying broad collection; proportionate security — encryption, strict access control, access logs; time-limited retention — when purposes end, delete/destroy under Article 14 by safe measures preventing unauthorised recovery; de-identification where possible — de-identified data is no longer personal data (Clause 1 Article 2), but Clause 6 Article 14 prohibits re-identification, except where otherwise prescribed by law.

Consent when processing sensitive data

Law 91/2025 does not set a separate “consent regime” for sensitive data, but Article 9 conditions applied to sensitive data demand greater caution. Requiring subjects to “clearly know” data types and processing purposes (Clause 2 Article 9) means companies must specifically and understandably explain the data’s sensitive nature and related risks. The per-purpose consent principle (point a Clause 4 Article 9) requires consent for sensitive data to be separate.

Good practice is designing separate, clear consent mechanisms for each sensitive data type: a separate checkbox for collecting biometric attendance data, a separate document for processing health information in employee insurance programmes. See consent management guidance.

Sensitive data in finance, banking and credit

Article 27 sets a specific responsibility framework for finance, banking and credit information activities. Responsibilities: fully implementing sensitive data protection regulations plus safety and security standards in finance and banking; not using credit information for credit scoring, credit ranking or credibility assessment without the subject’s consent; and notifying subjects when bank, financial or credit account information is leaked or lost.

For fintech, e-wallets, securities and insurance, these regulations all apply when processing customers’ financial data, because Article 4 of Decree 356/2025 classifies financial, securities and insurance information as sensitive data. Compliance practice: separating consent mechanisms for credit scoring; notification procedures when account data is leaked or lost; complete processing activity logs.

Health data and data in insurance business

Article 26 regulates personal data protection for health information and in insurance business: subject consent is required when collecting and processing — (e.g. medical emergency). Organisations and individuals in the health sector must not provide personal data to third parties that are healthcare or insurance service providers — except with the subject’s written request or in Article 19 cases.

Affected groups include: private hospitals and clinics; life and health insurance companies; online medical platforms and health-tracking apps; and FDI companies implementing employee health programmes. Note: periodic employee health check results organised by companies remain sensitive data — use only for notified purposes with consent, do not share with third parties without basis.

Location and biometric data

Article 31 specifically regulates two highly technological sensitive data types. Personal location data is data determined via positioning technology to know location and help identify specific persons. The Law prohibits tracking via RFID tags and other technologies, except with subject consent, competent authority requests, or otherwise prescribed by law. Mobile app platform providers must notify about location data use, prevent collection by unrelated parties, and provide location-tracking options to users. Biometric data is data about individual, stable physical attributes and biological characteristics — fingerprints, faces, irises, voices. Clause 4 Article 31 requires collectors and processors to: physically secure storage and transmission devices; restrict access rights; have monitoring systems to prevent and detect infringements; comply with laws and international standards. Where processing causes harm to subjects, collectors and processors must notify those subjects under Government regulations. For companies implementing fingerprint attendance, face recognition or AI cameras, these are direct obligations — see cameras, biometric data and compliance risks.

Employees’ sensitive data

Employees are the subject group whose sensitive data companies process most: biometric attendance, health information, payroll bank accounts, location data. Article 25 sets the framework: only request information serving recruitment, management and employment purposes under law; store data within prescribed or agreed periods; and delete/destroy when contracts end, except as agreed or otherwise prescribed by law.

Three practices to standardise now. First, biometric attendance: separate employee consent required, clearly notifying applied technological measures (Clause 3 Article 25), and security measures under Clause 4 Article 31. Second, health data: use only for correct purposes, do not share with third parties without basis. Third, after contract termination: delete sensitive data of departed employees, except data required by law to retain.

Impact assessment and technical measures for sensitive data

Processing sensitive data raises risk levels in impact assessment dossiers under Article 21 — and excludes companies from deferring this obligation (Article 38). In dossiers, companies need to separately identify each sensitive data type processed, assess corresponding risks and determine higher-level mitigation measures.

For technical measures, the Law suggests tools at Article 12 (encryption — encrypted data remains personal data) and Article 14 (de-identification). For sensitive data, companies should apply: encryption in storage and transmission; minimum-principle access control; complete access logs; separate storage environments for sensitive data; and safe deletion/destruction procedures when purposes end.

Compliance checklist and support from FLAT

Companies processing sensitive data should review against this checklist. (1) Classification: inventory and classify all sensitive data under Article 4 Decree 356/2025 — noting newly added groups versus Decree 13/2023. (2) Processing basis: determine the basis for each type — separate consent under Article 9 or consent-exempt cases under Article 19. (3) Impact assessment dossier: prepare and send dossiers under Article 21, with separate risk assessment for sensitive data (noting no deferral under Article 38). (4) Protection measures: encryption, access control, access logs, safe deletion. (5) Personnel: designate data protection departments and personnel meeting competency conditions under Article 33 — a mandatory, non-deferrable obligation. (6) Incident response: dedicated scenarios for sensitive data incidents, ensuring 72-hour notification under Article 23. See the general obligations framework of the Personal Data Protection Law. FLAT LAW FIRM supports FDI companies in inventorying and classifying sensitive data, drafting impact assessment dossiers, standardising consent mechanisms and building appropriate protection measures.

Frequently asked questions

What does the sensitive personal data catalogue under Decree 356/2025 include?

Article 4 of Decree 356/2025/ND-CP lists all groups — see the detailed catalogue in the opening section. Three expansions versus Decree 13/2023: legal violation data generally; financial data extended to securities and insurance; and online behavioural tracking data.

Does fingerprint attendance require separate employee consent?

Yes. Fingerprint data is biometric data — a sensitive data group under Article 4 of Decree 356/2025. Companies must have employee consent meeting Article 9, clearly notify applied technological measures (Clause 3 Article 25) and apply security measures under Clause 4 Article 31.

Can small companies processing sensitive data defer impact assessment obligations?

No. Clause 2 Article 38 allows small and startup companies to skip Articles 21, 22 and Clause 2 Article 33 for 05 years — but excludes cases directly processing sensitive personal data; household businesses and micro-enterprises directly processing sensitive data are also not exempt (Clause 3 Article 38).

Must encrypted data still comply with sensitive data regulations?

Yes. Clause 1 Article 12: personal data after encryption remains personal data. Encryption is encouraged (Clause 3 Article 12) but does not change the data’s legal nature. Only when data is de-identified to the point of no longer identifying a specific person does it cease being personal data (Clause 1 Article 2).

Can employee health data be kept after they leave?

In principle it must be deleted/destroyed. Clause 2 Article 25 requires deleting/destroying employees’ personal data when contracts end, except as agreed or otherwise prescribed by law.