Loading…
Loading…
The PDPL is the fifth instrument in Vietnam's digital-sovereignty stack — alongside the 2018 Cybersecurity Law / Decree 53/2022/ND-CP (cyberspace-service localization, filed as 2022-08-15-vietnam-decree-53-data-localization), Decree 13/2023/ND-CP (PDPD personal-data protection, sub-statutory predecessor), the 2024 Law on Data No. 60/2024/QH15 (horizontal data-governance, filed as 2024-11-30-vietnam-law-on-data-60-2024-qh15), and Decree 147/2024/ND-CP (social-media identity verification). The PDPL is not a consolidation but a statutory upgrade: by elevating personal-data protection from a Government decree (PDPD) to a National-Assembly statute, Vietnam puts the regime on equal footing with the Cybersecurity Law and the Law on Data.
Five structural features make the PDPL a meaningful escalation:
1. Revenue-based administrative penalties. The PDPL introduces tiered fines pegged to corporate revenue rather than fixed VND amounts: up to 5% of prior-year total revenue for cross-border data-transfer violations, up to 10x illegal gains for unlawful data trading, and a baseline cap of VND 3 billion (~USD 115k) for other breaches. This is the first GDPR-style revenue-pegged penalty in Vietnamese data law and a significant uplift over the Decree 13/2023 / Decree 14/2025 administrative fine schedule.
2. Extraterritorial scope. The law applies to (i) Vietnamese organisations / individuals processing personal data of Vietnam residents, (ii) foreign organisations offering goods or services to Vietnam residents, and (iii) any party transferring Vietnamese personal data abroad. Reaches non-resident SaaS, cloud, ad-tech, and fintech operators with no Vietnamese establishment.
3. Basic / sensitive personal-data tiers. Articulates two statutory data classes — basic personal data and sensitive personal data (health, biometrics, financial, location, sexual orientation, etc.) — with elevated consent, security, and transfer requirements for the sensitive tier. Covers both digital and non-digital (paper) records.
4. Statutory data-subject rights. Codifies rights to be informed, consent / withdraw consent, access, rectify, delete, restrict processing, and object — bringing Vietnam's data-rights catalogue into approximate alignment with GDPR Articles 13-21, though without the explicit right to data portability or automated-decision objection.
5. Prohibited acts. Article-level prohibitions on (i) using another person's personal data to commit unlawful acts, (ii) buying or selling personal data unless expressly permitted by law, and (iii) seizing, intentionally disclosing, or destroying personal data — backed by the new revenue-based penalty regime and potential criminal referral.
Operational details are filled in by Decree 356/2025/ND-CP (issued by the Government on 31 December 2025, effective 1 January 2026), 5 chapters / 42 articles, prescribing the consent mechanics, impact-assessment thresholds, cross-border transfer procedures, and breach-notification requirements.
AWS, Azure, GCP, Salesforce, Workday, ServiceNow, Adobe, and fintech / ad-tech operators face tightened cross-border transfer requirements layered on top of Decree 53 localization and the Law on Data's "important data" / "core data" catalogues. The revenue-pegged 5% ceiling is the first Vietnamese sanction framework with credible material impact on hyperscaler P&Ls.
Cloud, Viettel IDC, FPT Cloud, CMC Cloud benefit from elevated foreign-provider compliance friction; the PDPL's local-processing preference (a foreign provider can avoid cross-border-transfer scrutiny by hosting in-country) reinforces the Decree 53 / Law on Data localization gravity well.
e-wallets (MoMo, ZaloPay, ViettelPay), insurers, and platform marketplaces (Shopee VN, Lazada VN, Tiki, Tiktok Shop VN) must rebuild consent architectures, vendor / processor contracts, cross-border-transfer impact assessments, and data-subject- rights workflows by 1 January 2026. Sector-specific guidance from State Bank of Vietnam (banking) and Ministry of Industry and Trade (e-commerce) is expected through Q4 2025 / H1 2026.
consent rules raise ambiguity for foundation-model developers training on Vietnamese-language corpora; couples with Law No. 134/2025/QH15 (Vietnam AI Law, filed as 2025-12-10-vietnam-law-on-artificial-intelligence-134-2025-qh15) to create overlapping consent / training-data governance.
register.** Existing VN entries (Decree 53/2022, Law on Data 60/2024, Decision 1018/QD-TTg semiconductor, Decree 182/2024 Investment Support Fund, Law on Digital Technology Industry, Law on AI 134/2025) cover the cyberspace-service, horizontal- data, semiconductor-incentive, and AI tracks. The PDPL closes the personal-data perimeter at the statutory level.
ceiling or does multi-violation aggregation push effective exposure higher? Decree 356/2025 implementing rules will clarify.
filing requirements, and whether MPS pre-approval is required or merely notification.
also qualifies as "important data" or "core data" under the 2024 statute, which transfer regime governs (PDPL, Law on Data, or both)?
Decree 53 / Decree 147 pattern) or systematic registration sweep against foreign cloud / SaaS providers?
insurance regulators may issue sector-specific PDPL implementation rules; the PDPL itself does not pre-empt sectoral-regulator authority.