Data Protection Matters
← All privacy laws

Vietnam

Personal Data Protection Law

Law on Personal Data Protection (Law No. 91/2025/QH15, Luật Bảo vệ dữ liệu cá nhân)

Keywords

VietnamPDPLLaw 91/2025/QH15personal datadata subjectdata controllerconsentimpact assessmentcross-border transferdata breachMinistry of Public SecurityDecree 13/2023finessensitive data
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Law on Personal Data Protection, No. 91/2025/QH15, is Vietnam's first statute dedicated to personal data. The National Assembly passed it on 26 June 2025 and it took effect on 1 January 2026. It raises to the level of a law the rules that previously sat in Decree 13/2023/ND-CP, and it adds new duties, so organizations should expect further detail from implementing government decrees.

Who it applies to

The Law applies to Vietnamese agencies, organizations and individuals, to foreign organizations and individuals in Vietnam, and to foreign parties that directly take part in or are involved in processing personal data of Vietnamese citizens and people of Vietnamese origin. It separates the "data controller", the "data processor" and a party that does both. It treats personal data as basic or sensitive, with the lists of each category set by the Government.

Core principles

Personal data may be collected and processed only within a specific, clear and lawful scope and purpose. It must be accurate, updated where needed, and stored only as long as the purpose requires. Organizations must protect the data they hold and be able to show compliance, and the Law also sets rules for the processing of particular kinds of data, including children's data, employee data and health and insurance data.

Consent is the main basis. It is valid only if voluntary and given with knowledge of the key facts, including the type of data, the purpose, the controller, and the data subject's rights and duties. The Law also lists cases where data may be processed without consent, such as urgent protection of life, health or legitimate interests, national security and public order needs, state management, and carrying out an agreement with the data subject. Processing that existed under Decree 13/2023/ND-CP with consent can generally continue without fresh consent.

Individual rights

Data subjects have the right to be informed about processing, to give or refuse consent and to withdraw it, and to view and correct their data or ask for it to be corrected. They may also request that their data be provided, deleted or restricted, object to processing, and complain, sue or claim compensation. They also carry duties, such as providing accurate data and respecting the rights of others.

Key obligations

Controllers must prepare a data processing impact assessment and submit it to the specialized authority within a set period after processing begins, and update it when circumstances change. A violation that may harm national security, public order or the life, health or property of data subjects must be reported to the specialized authority within 72 hours of discovery. Organizations must assign a department or qualified personnel to protect personal data, or hire a service provider. Small enterprises and start-ups may opt out of some of these duties for the first five years, with exceptions for higher-risk businesses.

Cross-border transfers

Transfers include moving data stored in Vietnam to systems abroad, giving data to foreign parties, and using a platform outside Vietnam to process data collected in Vietnam. Anyone transferring data across borders must prepare a cross-border transfer impact assessment and submit it to the specialized authority within a set period after the first transfer. The authority can inspect transfers and can order a transfer to stop where national defense or security is at risk. Certain cases are exempt, such as transfers by competent state bodies and transfers by data subjects of their own data.

Enforcement and penalties

The Government manages data protection nationwide, and the Ministry of Public Security is the lead agency and hosts the specialized data protection authority. Violations can lead to administrative fines, criminal liability and compensation. For cross-border transfer violations by organizations, the maximum fine is 5% of the previous year's revenue. Buying or selling personal data can be fined up to ten times the revenue gained, and other violations carry a maximum fine of 3 billion dong, with individuals facing half the organizational maximum.

The official text

The authoritative version is the Vietnamese-language Law No. 91/2025/QH15, published in the Official Gazette (Công báo) of the Government of Vietnam. This summary relies on that text, and any English version is an unofficial translation. Use the official text, not this summary, for anything that matters.

Below is the source we understand to be the official text (Vietnamese, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →