EnglishVI
Vietnam flag

Vietnam

Vietnam Data Privacy Laws: Personal Data Protection Law 2025 Complete Guide

By Recording Law Editorial TeamReviewed May 20, 202621 min read
Vietnam Data Privacy Laws: Personal Data Protection Law 2025 Complete Guide

Frequently Asked Questions

What is Vietnam's primary data protection law?

Vietnam's primary data protection law is Law No. 91/2025/QH15 on Personal Data Protection, passed by the National Assembly on June 26, 2025, and effective January 1, 2026. It replaced Decree No. 13/2023/ND-CP, which had been Vietnam's first dedicated personal data protection regulation since July 2023. Implementing Decree No. 356/2025/ND-CP took effect on the same date.

When did Vietnam's new Personal Data Protection Law take effect?

Law No. 91/2025/QH15 took effect on January 1, 2026. The National Assembly passed the law on June 26, 2025. Decree 356/2025/ND-CP, the implementing decree, was issued on December 31, 2025, and also took effect on January 1, 2026. Both instruments replaced Decree 13/2023/ND-CP, which ceased to have legal effect on that date.

Does Vietnam require data localization?

Yes, for covered service providers. Decree 53/2022/ND-CP implementing the Law on Cybersecurity 2018 requires companies providing internet, telecommunications, and value-added services in Vietnam that collect and process Vietnamese user data to store that data on servers in Vietnam. Localization applies to personal data, user-generated content, and user relationship data. Foreign providers must comply within 12 months of receiving a written request from the Ministry of Public Security.

What are the penalties under Vietnam's Personal Data Protection Law?

Penalties include administrative fines of up to 5% of prior-year revenue for unlawful cross-border data transfers, with a minimum of VND 3 billion (approximately USD 115,000). Illegal buying and selling of personal data carries fines of up to 10 times the revenue earned from the illegal transaction. All other violations face a maximum fine of VND 3 billion for organizations. Serious violations can result in criminal prosecution with fines up to VND 1 billion and imprisonment up to 7 years.

Who enforces Vietnam's data protection laws?

The Ministry of Public Security (MPS), acting through its Department of Cybersecurity and High-Tech Crime Prevention (A05), is the primary enforcement authority. A05 receives data processing impact assessment dossiers and transfer impact assessments, investigates violations, and coordinates breach responses through VNCERT/CC. Sector-specific regulators including the State Bank of Vietnam also have enforcement roles within their domains.

What are the rules for transferring personal data outside Vietnam?

Any organization transferring personal data of Vietnamese residents outside Vietnam must file a Transfer Impact Assessment dossier with the MPS A05 department within 60 days of the first transfer. The dossier must describe the data, the purpose, the recipient, the security safeguards, and the contractual arrangements. Certain transfers are exempt, including state agency transfers, employee cloud storage, transfers by the data subject themselves, and transfers in national emergencies. The MPS has authority to suspend transfers that threaten national security.

Do small businesses need to comply with Vietnam's data protection law?

Small enterprises and qualifying startups have a five-year grace period through January 1, 2031, for certain obligations including DPIA filing and DPO appointment. However, this grace period does not apply if the organization processes sensitive personal data, serves as a data processing service provider, or processes data relating to more than 100,000 individuals. Micro-enterprises and household businesses are broadly exempt from DPO and DPIA requirements unless they fall within those carve-outs.

Does Vietnam require a Data Protection Officer?

Yes, organizations that process personal data must designate a qualified data protection department or appoint a qualified individual (DPO). In-house DPO candidates must hold at minimum a college degree, have at least two years of relevant experience, and have a background in law, IT, cybersecurity, data security, risk management, compliance, or HR. External data protection service providers must employ at least three qualified personnel. Small enterprises and startups are exempt for five years unless they handle sensitive data or large data volumes.

Updates

Major update: Added full coverage of Law No. 91/2025/QH15 on Personal Data Protection (passed June 26, 2025; effective January 1, 2026), Decree 356/2025/ND-CP, revenue-based penalties, DPO qualification requirements, sector-specific rules, and updated enforcement status. Previous version covered Decree 13/2023 only.

Sources and References

  1. Law No. 91/2025/QH15 on Personal Data Protection (English)(thuvienphapluat.vn)
  2. DLA Piper Data Protection Laws of the World: Vietnam(dlapiperdataprotection.com)
  3. Vietnam Personal Data Protection Law: A Closer Look - Tilleke & Gibbins(tilleke.com)
  4. Decree 356/2025: Guidance for Vietnam PDPL - Tilleke & Gibbins(tilleke.com)
  5. Vietnam Personal Data Protection Regulation Decree 356 - Vietnam Briefing(vietnam-briefing.com)
  6. KPMG Vietnam Legal Alert on Decree 13/2023(kpmg.com)
  7. Vietnam Data Localization Regulation - ITIF(itif.org)
  8. Vietnam Cross-Border Data Transfer Regulation - ITIF(itif.org)
  9. Vietnam Cybersecurity Data Localization Requirements - U.S. Department of Commerce(trade.gov).gov
  10. Vietnam New Personal Data Protection Law - Rouse(rouse.com)
  11. Decree 356: Personal Data Protection Operational Obligations - Acclime(vietnam.acclime.com)
  12. Vietnam Law on Personal Data Protection: Latest Developments - Vietnam Briefing(vietnam-briefing.com)
Share: