WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Vietnam Privacy & Data Protection Laws

Every regime below can apply to a business handling Vietnam residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

January 1, 2026
Law on Personal Data Protection
Vietnam PDPL
Verify details

Vietnam elevated its data-protection regime from a government decree to a full statute effective January 1, 2026. The PDPL applies to any agency, organization or individual processing personal data within Vietnamese territory regardless of nationality, and reaches foreign entities with no Vietnamese legal entity that collect data from Vietnamese users through an app, website, or service. Note the shape of that extraterritorial limb: it is anchored substantially on Vietnamese citizens and persons of Vietnamese origin residing in Vietnam rather than on a purely territorial 'people located in Vietnam' targeting test, making it narrower than GDPR Article 3 in some respects and broader in others — the triggers below are the closest honest fit, not a literal transcription. The law carries consent-centric processing rules, impact-assessment filings with the Ministry of Public Security, restrictions and filing duties around cross-border transfers, and turnover-linked penalties for certain violations. Implementing decrees continue to fill in detail; confirm the current decree set before finalizing a compliance program.

Law No. 91/2025/QH15, passed June 26, 2025 (replacing Decree No. 13/2023/ND-CP as the primary instrument)Read regulation →

Children & Minors Protections · 1

Verify details

Processing the personal data of a person under 16 requires the consent of their parent or legal representative, which in practice puts an age-verification obligation on social platforms, games and education technology serving Vietnamese users. This sits inside a framework that already treats consent as the dominant lawful basis and that, as the cross-border entry describes, counts storing data on a foreign server as an export. Marked 'check': the Law and its implementing Decree both took effect on January 1, 2026, the primary texts are Vietnamese-language, and no enforcement practice exists yet — confirm the precise scope of the legal-representative requirement and any exemptions before designing a consent flow.

Law No. 91/2025/QH15 on Personal Data Protection; Decree No. 356/2025/ND-CP of December 31, 2025Read regulation →

Cross-Border Data Transfer · 1

Verify details

Vietnam's definition of a transfer is the part that catches businesses out. Decree 356 treats as a cross-border transfer not just sending data to a foreign recipient but STORING personal data on server systems located outside Vietnam or on a foreign provider's cloud service, and processing Vietnamese-collected data on overseas platforms — so ordinary use of a non-Vietnamese SaaS or cloud region is in scope. Transfers require a cross-border transfer impact assessment dossier, which must be kept available for inspection by the data protection authority and submitted within 60 days of the transfer. Decree 356 exempts several categories, including cross-border personnel management, transfers to fulfil legal obligations, and transfers to perform contracts or procedures for cross-border transport, logistics, remittance and payment. Penalties for cross-border transfer violations run to 5% of the previous year's Vietnamese revenue. Marked 'check': the Law and Decree are very recent, the primary texts are Vietnamese-language, and enforcement practice does not yet exist.

Law No. 91/2025/QH15 on Personal Data Protection; Decree No. 356/2025/ND-CP of December 31, 2025Read regulation →

Data Security & Breach Notification · 1

January 1, 2026 (replacing Decree 13/2023/ND-CP)
Law on Personal Data Protection — notification of personal data protection violations
Vietnam PDPL breach duty
Verify details

Vietnam's first comprehensive personal data statute took effect January 1, 2026, replacing Decree 13/2023. Controllers, controller-processors, and third parties must notify the specialised personal data protection authority within 72 hours of DETECTING a violation likely to harm national defence or security or public order, or to affect an individual's life, health, honour, dignity, or property. The change from Decree 13 matters operationally: the clock now runs from detection rather than from occurrence, which is the first time Vietnam gave organisations room to confirm an incident before reporting. Where an attack on an information system creates a consumer-information cybersecurity risk, a separate 24-hour deadline applies. Marked 'check': the Law and its implementing decree are very recent, the primary text is Vietnamese-language, and enforcement practice is not yet established.

Law No. 91/2025/QH15 on Personal Data Protection; Decree No. 356/2025/ND-CPRead regulation →

Other Asia-Pacific jurisdictions