When GDPR took effect in Europe in 2018, it triggered a wave of privacy legislation across Asia that has been building ever since. India enacted its Digital Personal Data Protection Act. Japan strengthened its Act on the Protection of Personal Information. South Korea revised its Personal Information Protection Act. Thailand passed a comprehensive privacy law.
Vietnam’s contribution — Law No. 91/2025/QH15 on Personal Data Protection, enacted June 26, 2025 and effective January 1, 2026 — completes a significant shift for Southeast Asia. The region now has multiple comprehensive privacy frameworks in force, and Vietnam’s PDPL is among the most substantive.
If you use apps that handle your personal data as a Vietnam resident, or if you use apps built by companies operating in Vietnam, this law changed the rules for how that data can be collected, stored, processed, and transferred.
What the Vietnam PDPL Covers
Vietnam’s Personal Data Protection Law applies broadly. It governs:
- Vietnamese agencies, organizations, and individuals handling personal data
- Foreign agencies, organizations, and individuals operating in Vietnam
- Any foreign entity that directly processes personal data of Vietnamese citizens, regardless of where the processing happens
That last clause is significant. Like GDPR’s extraterritorial reach, the PDPL applies to companies outside Vietnam whose products or services handle Vietnamese users’ data. A company headquartered in Singapore, the United States, or Europe that processes personal information of Vietnamese residents falls under this law.
The implementing decree — Decree No. 356/2025/ND-CP — was issued on December 31, 2025, and took effect alongside the main law on January 1, 2026. It fills in the operational details: what impact assessments look like, what cross-border transfer requirements involve in practice, and how the exemptions work.
What Counts as Personal Data
The PDPL distinguishes between two categories of personal data.
Basic personal data includes information that can identify a person: name, date of birth, gender, residential address, nationality, phone number, email address, and similar identifiers. Most accounts and profiles include this category by default.
Sensitive personal data receives stronger protection and requires explicit consent in most circumstances. The sensitive category includes:
- Racial or ethnic origin
- Political views, religious beliefs, or similar philosophical commitments
- Health and medical information
- Genetic data
- Biometric data used for identification
- Financial data including account details and credit history
- Location data with sufficient precision to reveal personal routines
- Data about children under 16
- Criminal record information
Biometric data — facial geometry, fingerprints, iris scans — appears in the sensitive category. This matters for apps that use facial recognition, fingerprint scanning, or similar identity features, which face a higher bar for consent and processing justification.
Key Rights the Law Gives Individuals
The PDPL creates a set of data subject rights similar in structure to GDPR’s rights framework, though with some differences in scope and procedure.
Right to be informed. Before collecting your data, an organization must tell you what is being collected, why, how it will be processed, how long it will be kept, and whether it will be shared with third parties. This information must be provided in clear language.
Right to access. You can request access to the personal data an organization holds about you.
Right to correction. You can request that inaccurate personal data be corrected.
Right to deletion. You can request that personal data be deleted in certain circumstances — when it is no longer necessary for the purpose it was collected, when you withdraw consent, or when processing was unlawful.
Right to restrict processing. You can object to certain types of processing of your data.
Right to data portability. You can request your data in a format that allows you to move it to another service.
Right to object to automated decision-making. If an organization is making decisions about you using automated processing, you have rights around that process.
Right to complain. You can raise complaints with the Ministry of Public Security, which is the primary enforcement body for the PDPL.
Consent Requirements
Consent under the PDPL must be:
- Freely given — not conditioned on using a service if the data isn’t necessary for that service
- Specific — consent for one purpose doesn’t cover other purposes
- Informed — given only after the individual has received the required information
- Unambiguous — active agreement, not silence or pre-checked boxes
Consent for sensitive personal data requires even more explicit acknowledgment.
Organizations must keep records of consent they have collected and be able to demonstrate compliance if questioned. Consent obtained under the old legal framework (before January 2026) may need to be re-obtained if it doesn’t meet the new requirements.
Cross-Border Data Transfers
This is one of the PDPL’s most operationally significant provisions for international companies.
By default, transferring personal data of Vietnamese individuals outside Vietnam requires completing a Transfer Impact Assessment (TIA) and submitting it to the Ministry of Public Security within 60 days of initiating the transfer. The TIA assesses whether the receiving country or organization provides adequate data protection.
In practice, routine use of international SaaS platforms, cloud infrastructure, or third-party services based outside Vietnam constitutes a cross-border transfer subject to TIA requirements.
Exemptions exist. The PDPL creates specific exemptions from the TIA requirement for:
- Small businesses, startups, business households, and micro-enterprises (for five years from the law’s effective date)
- Storage of employee data on cloud services for internal use
- Personal data transferred by the individuals themselves
The small business exemption is meaningful but time-limited. Companies that fall under it now will need to build compliance infrastructure before the exemption period expires.
Enforcement and Penalties
The Ministry of Public Security is the primary enforcement authority for the PDPL. The implementing decree specifies a penalty structure that varies by violation severity.
Significant fines include:
- Up to 10 times the illicitly gained revenue from buying or selling personal data without authorization
- Up to 5% of an organization’s revenue in the preceding year for unauthorized cross-border data transfers
- Up to approximately USD 112,000 (VND 3 billion) for other violations
Organizations can face penalties; individuals responsible for violations within an organization can face up to half the organizational fine.
The PDPL also creates criminal liability for the most serious violations — deliberate illegal processing of sensitive personal data, or selling personal data at scale.
What This Means in Practice for App Users
If you are in Vietnam and use apps that handle your personal data:
You have new rights you can exercise. You can request access to what an app holds about you, ask for corrections, request deletion in appropriate circumstances, and withdraw consent you have previously given. These rights are legally enforceable under Vietnamese law.
Consent requests are now more meaningful. Apps subject to the PDPL must obtain proper consent before processing your data. Vague terms of service that bundle unlimited consent into account creation are not sufficient. If an app asks you to agree to something specific about data processing, the law now requires that agreement to be informed and specific.
Sensitive data has stronger protection. If you use health apps, financial apps, or any service that processes data about your physical or genetic characteristics, those categories of data require explicit, separate consent.
What This Means for Apps and Services
Companies that handle Vietnamese user data — wherever those companies are headquartered — face several operational requirements:
Appointing a data processing officer where required, responsible for compliance and as a contact for data subject requests.
Conducting data processing impact assessments for high-risk processing activities and submitting them to the Ministry of Public Security within the required timeframe.
Managing consent properly at the point of data collection, keeping records, and having processes for handling withdrawal of consent.
Managing cross-border transfers through Transfer Impact Assessments if data leaves Vietnam (subject to applicable exemptions).
Responding to data subject requests within the statutory timeframe.
These requirements apply regardless of where the company is based. The extraterritorial scope is explicit.
Vietnam and the Asia-Pacific Privacy Landscape
Vietnam’s PDPL enters force alongside a rapidly evolving regional landscape. India’s DPDP Act, which received its implementing rules in 2026, covers one of the world’s largest digital populations. Thailand’s PDPA, Indonesia’s Personal Data Protection Law, and South Korea’s revised PIPA all create GDPR-adjacent frameworks across the region.
The result is that Asia-Pacific privacy law is converging toward a consistent set of principles — meaningful consent, data subject rights, cross-border transfer controls, and enforcement with real penalties — even as the specific rules differ in important ways.
For individuals, this convergence is broadly good news. It means that regardless of which regional law applies to the apps you use, there is an increasingly clear expectation that your data will be handled with specific protections and that you have recourse when those protections fail.
The Underlying Principle
Vietnam’s PDPL is built around a premise that has become the standard foundation for modern privacy law: personal data belongs to the person it describes, not to the organization that collected it. Organizations are custodians, not owners. They can process personal data for legitimate purposes with proper consent, but the individual retains rights over it throughout.
That principle has implications that go beyond legal compliance. It shapes what kinds of relationships between users and apps are legitimate, what defaults should look like, and what controls individuals should be able to exercise over their own information.
The law makes those principles enforceable in Vietnam. Understanding them is useful regardless of which country’s law applies to your situation.