Data, Technology & Compliance

Personal Data Protection Law and Its Impact on Companies

Personal Data Protection Law and Its Impact on Companies

From 01/01/2026, the Personal Data Protection Law No. 91/2025/QH15 takes effect, establishing a unified legal framework for all personal data processing activities in Vietnam. At the same time, Decree 356/2025/ND-CP detailing its implementation also takes effect and replaces Decree 13/2023/ND-CP. For companies, especially FDI companies, the Law sets specific obligations on consent, impact assessments and breach notification, with sanctions up to 5% of revenue or VND 3 billion depending on the act.

New legal framework: Law 91/2025 and Decree 356/2025

The National Assembly passed Law No. 91/2025/QH15 on 26/6/2025; the Law takes effect from 01/01/2026 (Article 38). The Government issued Decree 356/2025/ND-CP on 31/12/2025 detailing a number of articles, effective from 01/01/2026, replacing Decree 13/2023/ND-CP. Notably, Law 91/2025 directly regulates in the law itself many contents previously only in decrees: maximum fines (Article 8), conditions for valid consent (Article 9), impact assessment dossiers (Articles 21, 22), 72-hour breach notification (Article 23), and sector-specific regulations such as labour, healthcare, finance — banking, advertising, digital platforms (Articles 24 to 32).

Scope of application: which companies are regulated

Under Article 1, the scope covers personal data protection activities in the territory of Vietnam, applying to Vietnamese agencies, organisations and individuals; foreign organisations and individuals in Vietnam; and also foreign organisations and individuals directly participating in or related to the processing of personal data of Vietnamese citizens. For FDI companies, an overseas parent company or a cloud service provider with servers outside Vietnam may fall within the scope when processing data of individuals in Vietnam.

The Law distinguishes three roles companies need to self-determine: personal data controller (deciding purposes and means of processing), personal data processor (processing at the controller’s request through a contract), and personal data controller-processor (both deciding and directly processing), together with the concept of third party (Article 2).

Foundational concepts companies need to distinguish

Article 2 provides 12 definitions. Personal data is data in digital form or other-format information identifying or helping to identify a specific person, including basic personal data and sensitive personal data; data after de-identification is no longer personal data. Personal data processing is defined very broadly: any activity affecting data such as collection, analysis, encryption, editing, deletion, destruction, de-identification, provision, disclosure, transfer. The classification of basic and sensitive is the key point because protection levels differ: basic data reflects personal identity and background factors common in transactions; sensitive data is tied to privacy rights, and when infringed directly affects lawful rights and interests. The specific list is issued by the Government in Articles 3 and 4 of Decree 356/2025/ND-CP.

Personal data protection principles companies must comply with

Article 3 sets six personal data protection principles. Three principles most directly affecting company operations: collecting and processing data only within specific, clear scope and purposes; ensuring accuracy, correction and updating when necessary and only storing for a period appropriate to the processing purpose; implementing synchronised institutional, technical and human measures appropriate to protect data. In practice, violations often lie in how organisations process: excessive collection, indefinite retention, lack of updating procedures.

Rights of data subjects and companies’ response obligations

Article 4 lists data subjects’ rights: to be informed about processing activities; to consent, not consent and withdraw consent; to view and edit; to request provision, deletion, restriction of processing; to object to processing; to complain, denounce, sue and claim damages. Clause 5 Article 4 requires controllers and controller-processors to promptly implement requests within statutory time limits — Decree 356/2025 specifies in Article 5: respond within 02 working days of receiving a valid request; withdrawal of consent, restriction and objection to processing within 15 days (20 days if the processor or third party must jointly implement); viewing, editing and data provision within 10 days (15 days if involving the processor or third party); data deletion within 20 days (30 days if involving the processor or third party). Complex cases may be extended once by a corresponding period, with reasons notified and necessity and reasonableness demonstrated.

Data subject consent and cases not requiring consent

Article 9 sets conditions for valid consent: based on voluntariness, with the subject fully aware of the data types, processing purposes, the data controller and their own rights and obligations. Consent is expressed by clear, specific means that can be printed and copied — including electronic form. Four principles in Clause 4 Article 9: consent per purpose; no condition requiring consent for other purposes; validity until the subject changes it; silence or non-response is not deemed consent. Article 19 lists cases not requiring consent: protecting life and health in emergencies; resolving emergencies and preventing crime; serving state agency operations; performing the subject’s agreement with relevant agencies, organisations and individuals; other cases under law. Companies processing under Article 19 must still establish monitoring mechanisms: processing procedures, appropriate protection measures, regular risk assessments, periodic inspections, receiving feedback.

Obligation to assess personal data processing impact

Article 21 requires controllers and controller-processors to prepare and archive personal data processing impact assessment dossiers, sending 01 original to the specialised authority within 60 days from the first day of data processing; processors prepare and archive under agreement with the controller. The assessment is conducted once for the entire operation period (Clause 2 Article 21) and updated under Article 22: periodically every 06 months when there are changes, or immediately updated upon reorganisation, termination, dissolution or bankruptcy; when changing the data protection service provider; or when arising or changing business lines. Companies already operating before the Law’s effective date must complete the dossier within 24 months at the latest, i.e. no later than 31/12/2027 (Clause 1 Article 39). Detailed guidance in the article on impact assessment dossiers.

Cross-border personal data transfers

Article 20 regulates three cases: transferring data stored in Vietnam to systems located outside Vietnam’s territory; organisations and individuals in Vietnam transferring data to overseas organisations and individuals; and using platforms located outside Vietnam’s territory to process data collected in Vietnam — such as cloud services, CRM, HR management software from foreign providers. The cross-border data transferor must prepare a cross-border personal data transfer impact assessment dossier, sending 01 original to the specialised authority within 60 days from the first day of transfer. The specialised authority may conduct periodic inspections (no more than 01 time/year) or ad hoc ones, and require suspension of transfers when discovering data transferred for use in activities that may harm national defence and security. No impact assessment is required in cases: transfers of competent state agencies’ data; storing employee data on cloud computing; subjects transferring their own data. In-depth analysis in the article on cross-border personal data transfers.

Breach notification and data incident response

Article 23 sets the notification obligation upon discovering violations of personal data protection regulations that may harm national defence, security, social order and safety, or infringe on the life, health, honour, dignity or property of data subjects: controllers, controller-processors and third parties must notify the specialised authority no later than 72 hours from discovery; processors discovering violations must promptly notify the controller; the controller must prepare confirmation minutes and coordinate handling; related parties are responsible for preventing violations and remedying consequences. The 72-hour mark counts from the moment of discovery, so companies need to record this moment with a basis (system logs, internal minutes). The full response process is in the article on data breach incident response.

Sanctions and compliance roadmap for companies

Article 8 sets three maximum fine levels: buying and selling personal data — up to 10 times the revenue from the violation (Clause 3), also a prohibited act under Clause 6 Article 7; organisations violating cross-border data transfer regulations — up to 5% of the immediately preceding year’s revenue (Clause 4); other violations — up to VND 3 billion (Clause 5); individuals face half the level applied to organisations (Clause 6). In addition to administrative fines, criminal prosecution and damages may apply. Suggested compliance roadmap: (1) inventory and classify data under Articles 3 and 4 of Decree 356/2025; (2) determine roles in each data flow; (3) standardise consent mechanisms under Articles 9 and 10 — see the article on consent management; (4) prepare and send impact assessment dossiers within 60 days; (5) review cross-border data flows and prepare corresponding dossiers; (6) designate data protection personnel or hire a service organisation under Article 33; (7) build data subject request handling procedures meeting the 02/10/15/20-day marks; (8) build incident response scenarios ensuring 72-hour notification. FLAT LAW FIRM supports FDI companies in implementing the above under Law 91/2025 and Decree 356/2025.

Frequently asked questions

When does Personal Data Protection Law 91/2025 take effect and what does it replace?

Law No. 91/2025/QH15 was passed on 26/6/2025, effective from 01/01/2026 (Article 38). Decree 356/2025/ND-CP detailing implementation, issued on 31/12/2025, effective from 01/01/2026, replaces Decree 13/2023/ND-CP. Consent agreements and impact assessment dossiers prepared under Decree 13/2023 before the Law’s effective date continue to be used under Article 39.

Must an overseas parent company comply with Law 91/2025?

Possibly. Article 1 applies also to foreign organisations and individuals directly participating in or related to the processing of personal data of Vietnamese citizens. If the parent company or the group’s service provider processes data of individuals in Vietnam, it falls within the scope, regardless of whether it has a legal presence in Vietnam.

Must small companies prepare impact assessment dossiers?

Under Clause 2 Article 38, small companies and startups may choose to implement or not implement Articles 21, 22 and Clause 2 Article 33 for 05 years from the Law’s effective date — except when doing data processing service business, directly processing sensitive data or processing data of a large number of subjects. Business households and micro-enterprises are exempt with the same exceptions (Clause 3 Article 38).

What is the maximum fine for violating cross-border data transfer regulations?

Under Clause 4 Article 8, violating organisations face a maximum of 5% of the immediately preceding year’s revenue. Individuals committing the same act face a maximum of half the level applied to organisations.

What must a company do within 72 hours of discovering a data leak?

Under Article 23, upon discovering violations that may harm national defence, security, social order and safety or infringe on the life, health, honour, dignity or property of data subjects, controllers, controller-processors and third parties must notify the specialised authority no later than 72 hours from discovery; at the same time prepare minutes, prevent violations, remedy consequences and coordinate handling.