On January 1 2026, Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 (PDPL) and Decree No. 356/2025/ND-CP (Decree 356) took effect, replacing Decree No. 13/2023/ND-CP. The PDPL operates alongside the Data Law 2024, effective from July 1 2025 (the Data Law), and the Cybersecurity Law 2025, effective from July 1 2026. These instruments make personal data compliance a governance issue, not a privacy-policy exercise.
Sensitive personal data and data trading
The PDPL distinguishes between basic and sensitive personal data. Decree 356 includes images of identity documents and account login credentials in the latter category. For organisations using optical character recognition or know-your-customer processes, this means mapping data flows, controlling access and retention, assessing vendors, and applying safeguards proportionate to the risk.
The law prohibits the purchase and sale of personal data, subject to statutory exceptions. The maximum fine for unlawful trading may equal 10 times the revenue obtained from the violation. Customer databases should not be treated as transferable commercial assets without a clear legal basis and appropriate controls.
Impact assessments and cross-border transfers
The PDPL and Decree 356 require a personal data processing impact assessment dossier (DPIA) and, where applicable, a cross-border transfer impact assessment dossier (CBTIA). These are not prior-approval mechanisms. The relevant parties must prepare and retain the dossiers from the start of processing or transfer, then submit them within 60 days. The specialised personal data protection authority assesses a dossier within 15 days and may require completion within 30 days.
A DPIA addresses the processing activities, data categories, recipients, security measures, risks, and mitigation, and includes the relevant processing agreement or contract. A CBTIA may be triggered by an overseas disclosure or by using an offshore platform to process personal data collected in Vietnam. It must address the overseas recipient, its data protection, transfer risks, and mitigating measures. Employment-related exemptions should be applied narrowly against their statutory conditions.
The exercise is not a one-off filing. Material changes may require an immediate update, and Decree 356 prescribes periodic updating in specified circumstances. In practice, businesses need ownership, a data inventory, contractual controls, and a process for keeping the dossiers current.
The interaction with the Data Law
The Data Law has a broader subject matter than the PDPL. It does not create a simple three-tier classification of ordinary, important, and core data. Instead, it regulates digital data generally and establishes a framework for important and core data; Decision No. 20/2025/QD-TTg identifies the relevant categories. A dataset may contain personal data under the PDPL and, depending on its content and scale, fall within an important or core data category.
For multinational groups, migration of customer or employee data to a regional platform should be reviewed through both lenses. The PDPL analysis asks whether a CBTIA is required and whether transfer safeguards are adequate. The Data Law analysis asks whether separate controls apply to important or core data. Keeping these workstreams distinct reduces the risk that either regime is overlooked.
Consent design and data-subject rights
Consent remains central to the PDPL; processing without consent is permitted in limited statutory circumstances. Consent must be voluntary, informed, and expressed in a verifiable form. Where different purposes require separate consent, organisations should obtain it separately and retain evidence of the individual’s decision.
This has direct implications for product design. Pre-ticked boxes, silence, continued browsing, and bundled acceptance of unrelated terms are not sound foundations for consent. An address collected to deliver an e-commerce order should not automatically be repurposed for marketing or analytics. Clear purpose notices, auditable records, and processes for withdrawal, restriction, and objection are more defensible than a single broad consent screen.
Final thoughts
The regime calls for integrated data governance. Organisations should identify processing and cross-border flows, determine each party’s role, and assign accountable personnel or a data protection function. They should align notices and consent journeys with actual uses, update vendor and intra-group arrangements, prepare the required dossiers, and build compliance into change management. This is more effective than treating the PDPL, Data Law, and cybersecurity requirements as isolated projects.