Data, Technology & Compliance

Privacy Notices for Companies in Vietnam

Privacy Notices for Companies in Vietnam

Most companies have already posted a privacy notice on their website — but few ask whether that document meets Vietnamese law. Under Personal Data Protection Law 91/2025/QH15 (effective 01/01/2026), a privacy notice is the tool for implementing the transparency obligation: helping data subjects “clearly know” data types, processing purposes, the controller and their rights before consenting (Article 9). This article guides building privacy notices under Law 91/2025 and Decree 356/2025/ND-CP.

Why companies must have a privacy notice

Law 91/2025 does not use “privacy notice” as a separate statutory term, but the transparency obligation permeates the Law. Clause 2 Article 9 requires consent to be valid only when the subject clearly knows data types, processing purposes, the controller and their own rights and obligations. Without providing this information clearly and systematically through a privacy notice, obtained consent can hardly be considered valid, and processing based on it risks being deemed non-compliant (Clause 4 Article 7).

Point a Clause 1 Article 4 recognises the right to be informed about processing activities as the first right of data subjects; Clause 4 Article 4 requires parties to facilitate, not obstruct, the exercise of this right. Clause 6 Article 29 requires organisations providing social networking and online communication services to publish privacy policies explaining how they collect, use and share data.

Privacy notices and consent: two sides of one mechanism

Privacy notices and consent are two complementary parts of the same mechanism: the notice implements the transparency obligation — providing the information Clause 2 Article 9 requires subjects to “clearly know”; consent is the subject’s legal act based on that information. The two documents must be built consistently: each processing purpose needs a corresponding consent mechanism (per-purpose, not bundled, withdrawable under Article 10); updating one means reviewing both. See guidance on data subject consent management.

Minimum contents of a compliant privacy notice

A privacy notice meeting Law 91/2025 needs the following content groups. First, controller identity: name, address, contact information — corresponding to what subjects must “clearly know” (point b Clause 2 Article 9). Second, collected data types: list specifically, distinguishing basic and sensitive data under Article 3 and Articles 3–4 of Decree 356/2025 — no vague phrasing like “other personal information”. Third, processing purposes: state each specific purpose (Clause 4 Article 9 requires consent expressed per purpose);

Fourth, processing basis: consent, or consent-exempt cases under Article 19 (e.g. contract performance, legal obligation compliance). Fifth, retention period: under the principle of retaining only for as long as appropriate to processing purposes (Clause 3 Article 3). Sixth, subject rights: list all rights under Clause 1 Article 4 and guide how to exercise them — with timelines under Article 5 of Decree 356/2025 (response within 02 working days; implementation in 10–20 days depending on request type). Seventh, security measures and contact information of the data protection unit. Eighth, complaint mechanism and notice updates when changes occur.

Privacy notices for websites and applications

Article 28 regulates data protection in advertising services: collecting data by tracking websites and applications is allowed only with subject consent; there must be means to refuse data sharing, defined retention periods, and deletion/destruction when no longer needed (Clause 8 Article 28). Article 29 requires social networking platforms and online communication services to offer options to refuse cookie collection and sharing, “do not track” options, and mechanisms to access, edit and delete data plus privacy settings.

For websites and apps, split notices into two layers — a summary at collection points (e.g. cookie banners, registration screens) with core information and clear consent/refuse buttons; and a full version easily accessible (usually in the footer). Under Clause 4 Article 9: do not bundle consent for multiple unrelated purposes into a single “agree” button; silence does not constitute consent. For behavioural advertising, also note anti-spam message and call regulations (Clause 4 Article 28).

Privacy notices for employees

Employment relations generate large volumes of personal data: recruitment files, contracts, attendance (including biometrics), health data, payroll bank accounts. Article 25 sets specific obligations: in recruitment, only request and use information serving recruitment purposes and other agreed purposes; delete/destroy unsuccessful candidates’ information, unless otherwise agreed. In management and employment, delete/destroy data when contracts end, unless otherwise agreed or prescribed by law.

Clause 3 Article 25 has a special point: processing employee data collected by technological/technical measures (CCTV, fingerprint/face attendance, monitoring software) is allowed only on the basis that employees clearly know of such measures and in compliance with law. Employee privacy notices should be separate documents (or annexes to labour regulations or staff handbooks), covering the data lifecycle from recruitment to contract termination.

Customer notices in finance and banking

Article 27 sets specific responsibilities for organisations and individuals in finance, banking and credit information — sectors processing large volumes of sensitive data. Beyond fully applying sensitive data regulations, these organisations must not use subjects’ credit information for credit scoring, ranking or credibility assessment without consent; collect only necessary data from appropriate sources; and must notify subjects when bank, financial or credit account information is leaked or lost.

For this group, privacy notices (usually confidentiality terms in account-opening or service contracts) need to state: specific processing purposes (scoring, credit ranking if any); collection sources and collecting/sharing parties; retention periods; consent withdrawal mechanisms; data deletion policies. Fintech, e-wallets, securities and insurance — though not traditional banks — all fall within scope when processing customers’ financial data.

Updating notices when processing purposes change

Privacy notices are not issued once and forgotten. Whenever processing purposes, data types, recipients or retention periods change, notices must be updated accordingly — because what subjects “clearly knew” when consenting (Clause 2 Article 9) is no longer accurate; new purposes need new consent based on updated information (point a Clause 4 Article 9). Good practice: every system or process change affecting personal data goes through legal review — like updating impact assessment dossiers under Article 22 — with notice versions archived with effective dates.

Multilingual privacy notices for FDI companies

Law 91/2025 does not prescribe mandatory languages, but for FDI companies whose data subjects are Vietnamese, a Vietnamese notice is a practical requirement to meet the “subject clearly knows” condition (Clause 2 Article 9) — an English-only document that ordinary readers cannot understand can hardly prove transparency. Recommendation: take the Vietnamese version as the governing text — reflecting actual processing in Vietnam, correctly citing Law 91/2025 and Decree 356/2025; English and Chinese versions are reference translations, with a clause giving Vietnamese priority in case of discrepancies.

Common mistakes when drafting privacy notices

Mistake one: copying foreign templates verbatim. GDPR or US-law templates cite concepts, rights and mechanisms not existing in Vietnamese law (e.g. “the right to be forgotten”), while missing Law 91/2025 specifics like request-handling timelines (Article 5 Decree 356/2025) or 72-hour breach notification (Article 23). Mistake two: content not matching reality. A notice stating “no sharing with third parties” while using three processing service providers — violating transparency and becoming adverse evidence when incidents occur.

Mistake three: bundling consent for all purposes — one checkbox “I agree to the privacy policy and terms of use” covering marketing, behavioural analytics and partner sharing, violating per-purpose consent (point a Clause 4 Article 9); mistake four: no consent withdrawal mechanism (Article 10 recognises the right to withdraw consent and restrict processing); mistake five: not updating — a notice from 2023 still citing Decree 13/2023 while Law 91/2025 is in force.

Reviewing and perfecting privacy notices with FLAT

A full review programme typically includes: comparing notice contents against actual processing (data inventory results); assessing completeness against the minimum content groups above; checking consistency across versions; updating legal bases under Law 91/2025 and Decree 356/2025; standardising consent collection mechanisms and evidence storage. For sensitive data, see guidance on sensitive personal data processing.

FLAT LAW FIRM supports drafting new or reviewing and refining privacy notice systems — from websites and applications to notices for employees and sector-specific customers — ensuring compliance with the current personal data protection legal framework and reflecting actual operations. Companies may contact us for advice on a review scope appropriate to their scale and sector.

Frequently asked questions

Does Law 91/2025 require companies to have a privacy notice?

The Law does not use “privacy notice” as a separately named obligation, but transparency is a through-running requirement: consent is valid only when the subject “clearly knows” (Clause 2 Article 9); subjects have the right to be informed (point a Clause 1 Article 4); some sectors like social networking must publish privacy policies (Clause 6 Article 29). Privacy notices are the standard tool for these obligations.

Can privacy notices be in English only?

Not advisable. The Law does not prescribe mandatory languages, but consent is valid only when the subject “clearly knows” the information (Clause 2 Article 9). For Vietnamese subjects not fluent in English, an English-only notice can hardly prove transparency. Recommendation: Vietnamese as the governing text, other languages as reference translations.

When must notices be updated and consent re-obtained?

When there are changes to processing purposes, data types, recipients, retention periods or any content the subject “clearly knew” when consenting (Clause 2 Article 9) — new purposes need new consent based on updated information. Tie notice reviews into change management procedures and archive versions over time.

How do employee privacy notices differ from customer ones?

They must cover the data lifecycle from recruitment to contract termination under Article 25: collect only for recruitment/management purposes; delete unsuccessful candidates’ data (unless otherwise agreed); delete data when contracts end (unless otherwise agreed or prescribed by law). When applying technological/technical measures (CCTV, biometric attendance), ensure employees clearly know (Clause 3 Article 25).

Can we use a GDPR-drafted privacy notice template?

Not advisable. GDPR templates cite concepts, rights and mechanisms not existing in Vietnamese law and miss Law 91/2025 specifics (request-handling timelines under Article 5 Decree 356/2025, 72-hour notification under Article 23, sectoral regulations at Articles 24–32). Adapt templates to the Vietnamese legal framework.