Publication
Publication
Contacts
Linh Bui
+84 28 3535 9745
Ngoc Anh Tran
+84 28 3535 9746
Supervisory Authority
Ministry of Information and Communications
National Legislation
Decree on Personal Data Protection
(Please note these links are provided for information only. Any translations may not be accurate and the text may not include amendments to that legislation).
Contributed by Allens
Last updated July 2026
General | Data Protection Laws
National Legislation
National Supervisory Authority
Scope of Application
Personal Data
Sensitive Personal Data
Data Protection Officers
Accountability and Privacy Impact Assessments
Rights of Data Subjects
Security
Transfer of Personal Data to Third Countries
Enforcement
ePrivacy | Marketing and cookies
National Legislation
Cookies
Marketing by E-mail
Marketing by Telephone
General data protection laws
Data privacy regulations are set out in a number of different legal instruments. The most important are the Law on Personal Data Protection (Law No.91/2025/QH15) (the "PDPL") dated 26 June 2025, and its implementing Decree No.356/2025/ND-CP ("Decree 356") dated 31 December 2025, which both came into force on 1 January 2026.
However, there are a number of other important instruments, including the Law on Cyber Security (Law No.116/2025/QH15) (the "LCS") (applies from 1 July 2026) – which regulates cybersecurity activities and the protection of national security in cyberspace, and Law on Data (Law No.60/2024/QH15) (applies from 1 July 2025) – which regulates the management and use of digital data (to the extent that such data constitutes personal data, the PDPL shall prevail).
Other relevant provisions can be found in the Constitution No.18/2013/L-CTN, the Civil Code (Law No.91/2015/QH13), the Penal Code (Law No.100/2015/QH13), the Law on Protection of Consumers’ Rights (Law No.19/2023/QH15), the Law on Electronic Transactions (No.20/2023/QH15), the Law on Digital Transformation (Law No.148/2025/QH15, which applies from 1 July 2026), the Law on Judicial Records (Law No.28/2009/QH12), the Law on Insurance Business (Law No.08/2022/QH15), the Law on Medical Examination and Treatment (Law No.15/2023/QH15), the Law on Telecommunications (Law No.24/2023/QH15), the Law on Credit Institutions (No.32/2024/QH15), the Law on Pharmacy (Law No.105/2016/QH13), the Law on Statistics (Law No.89/2015/QH13), the Law on Children (Law No.102/2016/QH13), the Law on Technology Transfer (Law No.07/2017/QH14), and the Law on Protection of State Secrets (Law No.117/2025/QH15).
Primary legislation tends to be generally drafted leaving its precise application open to interpretation. This interpretation is sometimes clarified by detailed regulations, but not in all cases. Therefore, application of the law to a particular set of facts is not always clear.
Currently, the Ministry of Public Security is drafting a decree on administrative penalties in the cyberspace sector (“Penalties Decree”) to complete the data privacy legal framework.
Entry into force
The PDPL and Decree 356 both came into effect on 1 January 2026.
The LCS came into effect on 1 July 2026.
Other laws referred to above came into effect on a number of different dates.
Details of the competent national supervisory authority
Under the PDPL and Decree 356, the Ministry of Public Security is the key authority which assumes the prime responsibilities for data privacy regulation.
Ministry of Public Security
96 Nguyen Du Street
Cua Nam Ward
Hanoi
Vietnam
Notification or registration scheme and timing
There is no general notification obligation. However, there are various trigger events that will require notification, namely: (i) general personal data processing (which require a personal data processing impact assessment); (ii) overseas transfer of personal data (which require an overseas transfer impact assessment); and (iii) the notification of a breach of personal data. These are all discussed in more detail later on in this summary. In addition to the above, there are other notification requirements, e.g., notification obligations to data subjects. The Law on Data also separately regulates data impact assessment requirements for the processing and cross-border transfer of non-personal data.
Exemptions to notification
There are exemptions to the obligation to notify overseas transfers. Exemptions are generally not applicable for other trigger events.
What is the territorial scope of application?
The PDPL may have extraterritorial application as it broadly captures: (i) Vietnamese agencies, organisations and individuals, including those operating overseas; and (ii) foreign agencies, organisations and individuals in Vietnam, or participating in or relating to the processing of personal data of (a) Vietnamese citizens or (b) persons of Vietnamese origin whose nationality has not yet been determined but who are living in Vietnam and have been issued with identity certificates.
The LCS contains a data localisation requirement where users' data in certain services must be stored in Vietnam as further discussed below.
Similarly to the PDPL, the Law on Data broadly captures (i) Vietnamese agencies, organisations and individuals, including those operating overseas; and (ii) foreign agencies, organisations and individuals in Vietnam, or participating in or relating to the processing of digital data.
Is there a concept of a controller and a processor?
Under the PDPL, a "Data Controller" means the organisation or individual that decides the purpose of, and means for, personal data processing.
A "Data Processor" means the organisation or individual that processes personal data at the request of the Data Controller or the Data Controller-Processor (as explained below) on a contractual basis.
The PDPL also provides for a "Data Controller-Processor" which is the organisation or individual that carries out the activities of both a Data Controller and a Data Processor, and has their corresponding obligations in the relevant capacity.
There is also a definition of “Third Party”, being the organisation or individual other than the data subject, Data Controller, Data Controller-Processor and Data Processor, that participates in the processing of personal data in accordance with law.
Other laws related to personal data also have their own definitions, which most commonly refer to “Processing Organisations”, being entities processing personal data.
Are both manual and electronic records subject to data protection legislation?
The other laws discussed above do not make any specific distinction between manual and electronic records. Therefore, both types of records would be subject to the same data protection regulation.
Are there any national derogations?
Not applicable.
What is personal data?
Personal data is defined by the PDPL as digital data or information in any other form which identifies or helps identify a specific natural person. Personal data after de-identification shall no longer be personal data.
Personal data is further classified into "basic personal data" and "sensitive personal data". The PDPL, together with its implementing Decree 356, includes non-exhaustive and descriptive lists of basic personal data and sensitive personal data.
Basic personal data includes: (i) surname, middle name and given name at birth, and other names (if any); (ii) date of birth; date of death or missing; (iii) gender; (iv) place of birth, registered place of birth declaration, registered permanent residential address, registered temporary residential address, current residential address, place of origin, and contact address; (v) nationality; (vi) individual's photo; (vii) telephone number, personal identification number, passport number, driver's licence number, and vehicle registration plate number; (viii) marital status; (ix) information about family relationships (parents, children or spouse); (x) information about the digital account of the individual; and (xi) other information associated with a specific person or helping identify a specific person which is not stipulated in the list of sensitive personal data. "Sensitive personal data" will be discussed below.
Certain definitions of “personal information” can also be found in alternate laws which is broadly in line with the PDPL. In other legal instruments, personal data also includes personal secrets and the concept of personal privacy (see below).
The concept of personal data includes information about the deceased (i.e., data of death), which continues to be subject to protection under the PDPL. However, it remains unclear under the PDPL how the protection of this information is to be enforced.
Is information about legal entities personal data?
No. However, if information about legal entities includes information that meets the definition of personal data, for example, information about employees, the information is considered personal data.
What are the rules for processing personal data?
The PDPL captures a wide range of data processing activities. Personal data processing is defined as the activities that impact personal data, comprising one or more of the following activities: collecting, analysing, compiling, encrypting, decrypting, modifying, deleting, destroying, de-identifying, providing, publicizing and transferring personal data and other activities that impact personal data.
Under the PDPL, consent remains the key (but not the only) basis for processing personal data, and is subject to various stringent rules in order to be valid (see below).
Personal data can be processed without consent of the data subject based on one of the following grounds: (i) in order to protect the life, health, honour, dignity, and lawful rights and interests of data subjects or others in emergency cases, or to protect legitimate rights or interests of others or the interests of the State against acts of infringement; (ii) in order to resolve a state of emergency or a threat to national security but not to the extent of declaring a state of emergency, or to prevent and combat riots, terrorism, crimes and breaches of law; (iii) serving activities of State agencies and State management activities in accordance with law; (iv) implementing agreements between data subjects and relevant agencies, organisations and individuals in accordance with law; and (v) other cases as prescribed by law.
The processing of personal information for national defence and security purposes, social order and safety or for non-commercial purposes must comply with other relevant laws.
Are there any formalities to obtain consent to process personal data?
Under the PDPL, in order for consent to be valid, it must satisfy various conditions. Particularly, the consent to process personal data is only effective if such consent is given on a voluntary basis and the data subject is fully aware of: (i) the type of personal data to be processed and the processing purpose; (ii) the identity of the Data Controller or Data Controller-Processor; and (iii) the rights and obligations of the data subject.
The consent to be granted must be express and specific, and can be withdrawn by the data subject. In principle: (i) consent must be given for each specific purpose; (ii) consent must not be accompanied by a condition that the data subject is bound to agree to purposes other than those agreed; (iii) consent is effective until the data subject changes such consent or as prescribed by law; and (iv) silence or no response shall not be considered as consent.
Consent from the data subject must be in a printable, and copyable format, including in electronic or verifiable format. Data Controller and Data Controller-Processor must store data subjects' consent. In case of dispute, the Data Controller or Data Controller-Processor is responsible to prove that consent has been obtained.
Are there any special rules when processing personal data about children?
Under the PDPL and Law on Children, it is prohibited to disclose the personal data of a child without the consent of the child’s parents or guardian and the consent of the child in question (where such child is over the age of 7 but younger than 16 years old). There is also a general obligation on agencies, organisations and individuals operating online to apply measures for ensuring the safety and personal secrets for children.
Are there any special rules when processing personal data about employees?
Under the PDPL, employers must comply with special rules on personal data protection in recruitment, management and employment of employees.
In particular, in recruitment, employers must: (i) only collect personal data necessary for recruitment and use it strictly for recruitment or other agreed lawful purposes; (ii) obtain the candidate’s consent for data processing; and (iii) delete or destroy provided data of the candidate if such candidate is not subsequently employed (unless otherwise agreed).
During employment, employers must: (i) comply with applicable data protection and labour laws; (ii) retain employee data only for the legally prescribed or agreed period; and (iii) delete or destroy such data upon termination of employment unless otherwise required by law or agreed with the employee. In addition, where technological measures are used in managing employees, these must be lawful and transparent to employees and implemented in a way that protects their rights; any data collected through unlawful means must not be used.
Other than the above, the Labour Code does not impose specific obligations on employers to protect personal data of employees. However, the employer, as one party to the employment contract, has an obligation under the Civil Code to keep confidential information received from the employee and not to use such information for the private purposes of such party or for other illegal purposes.
What is sensitive personal data?
Sensitive personal data is defined under the PDPL to be personal data associated with individual privacy which, when being infringed, will directly affect legal rights and interests of agency, organisation or individual.
Sensitive personal data includes: (i) data revealing racial origins and ethnic origins; (ii) viewpoints on politics, religion and belief; (iii) information about private life, personal secrets and family secrets; (iv) health status; (v) biometric data and genetic characteristics; (vi) data revealing sexual life and sexual orientation of an individual; (vii) data on crimes and breaches of law as collected and stored by law enforcement agencies; (viii) positions of individuals determined via location services; (ix) information about usernames and passwords for accessing electronic identification accounts of individuals; images of identity cards, citizen's identity cards and people's identity cards; (x) usernames and passwords for access to bank accounts; bank card information; data on transaction history of bank accounts; financial, credit information and information about financial, securities and insurance transaction history and activities of clients at credit institutions, foreign bank branches, organisations providing services of intermediary payment, securities and insurance, and other licensed organisations; (xi) data monitoring acts and activities of using telecom services, social media, online communication services and other services in cyberspace; and (xii) other personal data required to be kept confidential by law or requiring strict security measures.
Vietnamese law also provides for the concept of personal privacy or personal secrets and considers any such related information as personal data. This includes any information that a data subject may wish to keep confidential, such as medical records, tax payment dossiers, social insurance numbers, credit card numbers and other information defined by law.
Are there additional rules for processing sensitive personal data?
A party that handles sensitive personal data has extra obligations to: (i) formulate regulations on limited authorisation of access, procedures for processing and security measures; (ii) notify data subjects that the data to be processed is sensitive personal data when seeking their consent; and (iii) implement enhanced safeguards for transfers of sensitive personal data, including physical security measures for storage and transmission systems, encryption, anonymisation and other appropriate security measures during the transfer process.
There are some additional protections for personal privacy or personal secrets. For example, state agencies holding personal secrets must protect that information and only supply or share it with competent third parties in limited cases by law. Vietnamese law also provides additional protection for medical records, for persons participating in clinical trials of a drug, and for customer data in the banking sector.
Are there additional rules for processing information about criminal offences?
Under the PDPL, data of crimes collected and archived by law enforcement agencies is classified as a type of sensitive personal data and is subject to the processing requirements for that type of data.
The Law on Criminal Procedures allows a Court to hear a case in closed session. This applies in cases involving protection of persons aged below 18 or cases affecting personal privacy as per the litigant's request. However, the judgments must be pronounced publicly.
The Law on Judicial Records provides that no person or organisation may require an individual to provide their criminal record, except in limited cases where another law expressly requires the submission of such record, such as for recruitment, appointment, licensing or certification in sectors relating to national security, public order and safety, or other regulated industries.
Are there any formalities to obtain consent to process sensitive personal data?
There are no special formalities to obtain consent to process sensitive personal data and the same rules as for personal data apply (see above).
The PDPL further emphasises that the data subject would need to be aware that the personal data to be processed are of sensitive nature and the consent to be obtained must be in printable and copyable format (among other requirements).
When must a data protection officer be appointed?
The PDPL requires agencies and organisations to designate either internal personnel or a department responsible for personal data protection (“DPO”), or to engage external providers of personal data protection services.
Where an internal DPO is appointed, such appointment must be formalised through an official document setting out the assigned roles, functions, duties, powers and other relevant requirements.
There are some qualifications applicable to a DPO (e.g., at least two years of experience in some relevant areas for internal DPO) but no specific requirement that the DPO must be Vietnamese or Vietnam-based. DPO information will need to be listed in the relevant impact assessment dossiers (as discussed below).
What are the duties of a data protection officer?
Under Decree 356, a DPO generally has a range of governance, operational and advisory responsibilities, including: (i) organising the development of policies, procedures, regulations and standard forms to ensure compliance with personal data protection laws; (ii) facilitating the exercise of data subject rights; (iii) periodically assessing compliance status; (iv) preparing impact assessment dossiers and handling breach reporting; developing and implementing training programmes; (v) overseeing the implementation of technical measures to safeguard personal data confidentiality; and (vi) conducting research and advising on matters relating to personal data protection.
Is there a general accountability obligation?
Under the LCS, a cyberspace service provider in Vietnam is generally required to apply necessary management and technical measures to protect personal data.
The same principle is adopted under the PDPL, where parties processing personal data are required to apply technical and organisational measures to prevent breaches of personal data protection regulations and to prevent data loss or any damage to personal data.
Are privacy impact assessments mandatory?
Under the PDPL, Data Controllers, Data Controller-Processors and Data Processors are required to conduct a personal data processing impact assessment ("IA") and maintain the IA dossier from the time they start personal data processing. The IA is conducted once for the entire duration of operation and updated in accordance with the law.
The dossier includes: (i) a report on personal data processing impact assessment in the prescribed form; (ii) copies of agreements on personal data processing which are binding upon and reflects responsibilities between the parties engaging in the data processing activities; and (iii) policies, procedures, regulations, standard forms and other documents in relation to protection of personal data.
The report in limb (i) above must contain key details such as contact details of the Data Controller/Data Controller-Processor/Data Processor and their DPO, description of the purpose of personal data processing, types of personal data to be processed, details of processing activities and data flow diagrams, how consent of data subjects is sought, storage and deletion policies, safety plans and protective measures, results of compliance assessment, and assessment of the level of effect and risk of the processing activities.
In addition to the above, any party which transfers personal data of Vietnamese citizens offshore (except exemption cases discussed above) is required by the PDPL to conduct an IA for overseas transfer (see below).
For both types of IA dossiers, the relevant party must submit the IA dossier to the specialised agency for personal data protection within 60 days after starting data processing or cross-border transfer. The PDPL and Decree 356 do not expressly indicate which agency is the specialised agency for personal data protection. In practice, the Department of Cyber Security and High-Tech Crime Prevention under the Ministry of Public Security (A05) continues serving as the supervising authority for the data protection framework generally and the IA dossiers in particular. The authority will review and can request an update of the dossier.
To the extent that data is not personal data, the Law on Data separately requires impact assessment dossiers in respect of the processing or overseas transfer of important data and core data. "Important data" means data that may affect national defence, national security, foreign affairs, macroeconomic stability, social stability, public health, or public safety, and falls within the categories issued by the Prime Minister. "Core data" means a subset of important data that directly affects the foregoing interests and falls within the categories issued by the Prime Minister. The lists of important data and core data are issued from time to time by the Prime Minister.
Privacy notices
Under the PDPL, Data Controllers and Data Controller-Processors must formulate clear processes, procedures and standard forms to exercise rights of data subjects and must ensure that data subjects are notified of the procedures for the exercise of their rights. Data Controllers and Data Controller-Processors must also notify data subjects of the scope and purpose of the collection and use of their personal data prior to processing, save for cases where consent has been obtained (see above).
Rights to access information
Data subjects can access their personal data in order to review, rectify or request rectification of their personal data, and can also request their personal data from Data Controller/Data Controller-Processor.
Rights to data portability
The PDPL does not provide an express right to data portability. The PDPL provides the right to request provision of personal data, which is broad and distinct from a structured portability right in the GDPR, as it does not include a right to have data transmitted directly to another controller.
Right to be forgotten
Under the PDPL, where a data subject requests that a Data Controller/Data Controller-Processor updates, amends, or deletes their personal data, or withdraws their consent to personal data processing, the Data Controller/Data Controller-Processor must: (i) acknowledge the data subject's request within two working days, regardless of the type of request, and (ii) take appropriate actions within a statutory timeframe of 10 to 30 days (subject to any permitted extension).
The Data Controller, Data Controller-Processor and Data Processor must permanently delete any stored personal data in the cases prescribed by law, including where: (i) the data subject validly requests deletion; (ii) the purpose of processing has been fulfilled; (iii) the retention period has expired; (iv) a competent State authority issues a decision requiring deletion; (v) deletion is required under agreement; or (vi) other circumstances prescribed by law apply. Deletion must be carried out using appropriate security measures and must prevent unauthorised access to, or restoration of, the deleted or destroyed personal data. Similar provisions can be found in other laws referred to above.
Objection to direct marketing and profiling
The consent of the data subject is required in order to use personal data for the purposes of direct marketing. The data subject has the right to object to the Data Controller or Data Controller-Processor processing their personal data in order to prevent or restrict the disclosure of personal data or the use of personal data for advertising and marketing purposes. The Data Controller or Data Controller-Processor must acknowledge the objection request within two working days and implement the request within 15 - 20 days (subject to any permitted extension).
Other rights
The PDPL also provides the data subject with other rights including: (i) the right to request restriction on processing; (ii) the right to file complaints, denunciations and lawsuits; (iii) the right to claim damage; and (iv) the right of requesting competent agencies and relevant agencies, organisations, and individuals involved in personal data processing, to implement measures to protect personal data.
Security requirements in order to protect personal data
Under the PDPL, a Data Controller, Data Processor or Data Controller-Processor may be held liable to the data subject for any damage caused by its data processing activity. They must also: (i) set up internal policies for personal data protection; and (ii) implement appropriate managerial and technical measures to protect personal data in accordance with law, and review and update such measures when necessary.
Under the LCS, a cyberspace service provider in Vietnam must take appropriate managerial or technical measures to protect personal data. Information systems are classified into five security levels based on the extent of potential harm to national security, social order and safety, the lawful rights and interests of organisations and individuals, and the public interest in the event of incidents or violations of cybersecurity laws.
Information system administrators must: (i) regularly monitor and check systems to detect and address security threats (e.g., malware, vulnerabilities, unauthorised access); (ii) implement appropriate technical and organisational measures to prevent cyber threats and protect confidential information (including personal data); and (iii) cooperate with and comply with instructions from competent cybersecurity authorities.
Specific rules governing processing by third party agents (processors)
A third party agent (or a Data Processor) must have a data processing agreement with the Data Controller. While there is no template agreement, such data processing agreements should at a minimum include the following required contents: (i) purpose of the data transfer; (ii) relevant data subjects and types of data to be transferred; (iii) duration of processing and requirements on deletion of personal data upon completion of the data transfer purpose; (iv) legal basis for the data transfer; (v) responsibilities in respect of data protection during the data processing; (vi) responsibilities in respect of enabling rights of data subjects; and (vii) responsibilities in respect of cooperation and compliance in case of a breach.
Notice of breach laws
The PDPL requires that in the event of a breach of personal data protection regulations, the Data Processor must promptly notify the Data Controller upon discovery of such breach. The Data Controller or Data Controller-Processor must notify the specialised agency for personal data protection using the statutory notification form no later than 72 hours from the time of discovery of the breach, make minutes to record the breach and cooperate with the authority to handle the breach. In case of a breach of location data or biometric data, the data controller must also notify the affected data subjects within 72 hours and keep records of the breach for 5 years after resolving it.
Under the LCS, a cyberspace service provider in Vietnam has to notify the user and report to the cybersecurity task force in the event of disclosure of, damage to or loss of data about user information. Agencies, organisations and individuals using cyberspace have to promptly provide information relating to cybersecurity to the competent agency and cybersecurity task force.
Restrictions on transfers to third countries
Any party that wants to transfer personal data of Vietnamese citizens offshore must complete the cross-border transfer IA dossier (unless exempt, see below).
The IA dossier is conducted once for the entire duration of operation and updated in accordance with the law. The dossier must include key details such as contact details of the data transferor and recipient, the purpose of cross-border personal data transfer, types of personal data to be transferred, details of the transfer and processing activities, how consent of data subjects is sought, the plan for ensuring safety of personal data after cross-border transfer, and an assessment of the level of protection of personal data of the recipient and the level of effect and risk of the transfer. As part of the IA dossier, a copy of the contract or document on personal data transfer which is binding upon and reflects responsibilities between the transferor and recipient must be submitted.
The relevant transferring party must submit the IA dossier to the specialised agency for personal data protection within 60 days from the beginning of the relevant cross-border transfer. Where the dossier is incomplete, the specialised agency will request completion within 30 days; failure to comply may result in administrative penalties.
Notification of overseas transfer of personal data is exempted in the following cases: (i) press and communication activities carried out in accordance with law; (ii) overseas transfer of personal data which has been lawfully made public; (iii) emergency situations where cross-border data transfer is genuinely necessary to protect an individual's life, health or property, or to perform legal duties and obligations; (iv) overseas transfers for personnel management in accordance with labour regulations and collective labour agreements; and (v) transfers necessary for entering into contracts or implementing the procedures relating to cross-border transportation, logistics, money transfer, payment, hotels, visa applications, and scholarship applications.
The specialised agency for personal data protection can decide to inspect the offshore transfer no more than once per year or on an ad-hoc basis where it detects a breach of personal data protection regulations or any incident involving the disclosure or loss of personal data. The specialised agency may also require a cross-border data transferor to suspend the transfer of personal data where:
(i) the transferred personal data is used for activities that infringe national defence or national security; or (ii) there is a breach of personal data protection regulations that may harm national defence or national security.
In addition to the above, the LCS obliges certain enterprises providing internet services in Vietnam to store certain users' data in Vietnam. The Law on Data also requires separate IA dossier for the overseas transfer of important data or core data, to the extent such data does not constitute personal data.
Notification and approval of national regulator (including notification of use of Model Contracts)
The Data Controller, Data Controller-Processor, Data Processor or Third Party that transfers personal data of Vietnamese citizens offshore must conduct an IA and submit the dossier to the specialised agency for personal data protection within 60 days after starting the cross-border transfer (see above).
Use of binding corporate rules
There is no ability to use binding corporate rules in respect of transfers to third countries.
Fines
Under the PDPL, the maximum administrative penalty for organisations that violate cross-border personal data transfer regulations is 5% of the organisation's revenue in the preceding year. The maximum penalty for buying or selling personal data is 10 times the proceeds derived from the violation. In either case, where there is no revenue or proceeds (as applicable) or the amount calculated on that basis is lower than the general maximum, the general maximum fine of VND 3 billion (~US$ 113,700) for other personal data protection violations applies. For individuals, the maximum fine is half of the applicable amount for organisations.
Currently, regulators are working on a draft Penalties Decree on administrative penalties in the cybersecurity space. The latest draft Penalties Decree publicly available proposes certain sanctions for violations in processing personal data. In certain cases, repeated breaches may even result in an administrative fine of up to 5% of the revenue in the previous financial year, among other penalties.
As sanctions for specific violations are still in the pipeline under the draft Penalties Decree, sanctions for violations of personal data regulations are currently scattered across various regulations. Particularly, infringement of privacy laws may lead to fines for: (i) collecting personal data without the consent of the data subject; and (ii) publishing personal secrets or other personal data without the consent of the data subject; or (iii) failing to keep necessary management and technical measures to ensure the safety of personal data of other persons; or (iv) supplying personal data of other persons to a third party in a network environment. These fines can vary between VND10 million (~US$ 379) and VND60 million (~US$ 2,274).
Consumers’ personal data in e-commerce activities is also protected by administrative fines including: (i) for developing policies to protect personal data which are not compatible with regulations, not showing consumers the policies for personal data protection before or at the time of collecting such data, or failing to check, update, amend or cancel personal information when requested by the subject of information to do so; (ii) failing to set up a mechanism for receiving and resolving complaints from consumers or not implementing policies to ensure safety and security for the collection and use of personal data of consumers; or (iii) for collecting personal data of consumers without the consent of the data subject, setting up a default mechanism to force consumers to agree that their personal data be shared, disclosed or used for the purposes of advertising and other commercial purposes, or using the personal information of consumers improperly with the purpose and the notified scope. These fines can vary between VND2 million (~US$ 76) and VND60 million (~US$ 2,274). Besides monetary fines, e-commerce activities may be suspended for 3 to 6 months for a violation of point (iii).
In addition, stealing, using, revealing, transferring or selling information relating to trade secrets of other business persons or personal data of customers in e-commerce activities without consent from related parties can be punished by administrative fines of between VND60 million (~US$ 2,274) and VND80 million (~US$ 3,032) and confiscation of means of violation and suspension of e-commerce activities for 6 to 12 months.
Imprisonment
Certain infringement of privacy laws may subject the violators to criminal liabilities, including imprisonment. Particularly, infringement of privacy and security of mails, telephones, telegrams or other forms of private communication may be subject to maximum three years’ imprisonment (among others), but this would only apply after having been subject to administrative penalties.
Further, disclosure of personal data of individuals or business data of organisations on the Internet and telecom networks without consent which results in illegal profit of more than VND200 million (~US$ 7,580) may lead to criminal penalties of up to seven years' imprisonment (among others).
Illegal accessing of computer networks, telecommunications networks and electronic devices of other persons, subject to the nature and severity of the breach, may result in criminal penalties of up to 12 years' imprisonment (among others).
Compensation
Under the Civil Code, if personal data rights are infringed, the data subject is entitled to demand or request a competent body or person to compel the infringing party to compensate the data subject.
Other powers
Not applicable.
Practice
There have been some cases of regulators imposing administrative fines for breaches of personal privacy, mostly in a network environment. There have also been reported cases of criminal sanctions being imposed on acts of illegally accessing and stealing personal information for sale.
As regulations on personal data protection develop, we have seen more enforcement actions in this space. There is no exact statistic on the number of enforcement actions taken in the last 12 months and the majority of enforcement actions are not publicly disclosed.
ePrivacy laws
There is no specific ePrivacy law in Vietnam. However, the PDPL, the LCS, the Law on Digital Transformation and Law on Electronic Transactions contain some provisions that address ePrivacy issues.
Conditions for use of cookies
The use of cookies is not specifically regulated under Vietnamese law. However, personal data collected via the use of cookies is subject to Vietnamese privacy laws in the same manner as other personal data.
Regulatory guidance on the use of cookies
Since the use of cookies is not regulated, the guidance for storing personal data in cyberspace by using cookies is the same as the rules that apply to the management and processing of personal data which requires the consent of the data subject.
Conditions for direct marketing by e-mail to individual subscribers
Pursuant to Decree 91 dated 14 August 2020 on Anti-Spam Messages, Emails and Calls ("Decree on Anti-Spam"), advertisers via emails are only permitted to send advertising emails to users after users have provided express consent on receiving such advertising emails.
Advertisers must also provide a clear mechanism for users to opt-out from receiving advertising emails. As soon as advertisers receive opt-out requests from users, advertisers must acknowledge receipt of opt-out requests and stop sending advertising emails to users who opted out.
There are further requirements for advertisers to store subscription and opt-out requests and confirmation and to provide searching and storing tools so users can access these documents, among other obligations.
An advertiser is only permitted to send a maximum of three emails to one user within 24 hours, unless otherwise agreed with the user. Contents of the advertising emails must comply with laws on advertising.
Conditions for direct marketing by e-mail to corporate subscribers
The rules are the same as for individual subscribers.
Exemptions and other issues
Decree on Anti-Spam provides for other requirements. In particular, email subject and content must be consistent and advertising content must comply with laws on advertising. Advertising emails must be labelled with [QC] or [AD] at the beginning of the email subject to indicate that this is an advertising email. Advertisers must provide information such as name, telephone, email address, geographical address, and website, social network (if any). This information must be expressly set out in the email and must be provided immediately before the select function permitting the recipient to opt-out of email marketing. Where the advertising email concerns a chargeable service, the email must provide information on the fees to be charged. Further, an advertising email must include a function permitting users to opt out from receiving advertising emails.
Conditions for direct marketing by telephone to individual subscribers (excludes automated calls)
Under Decree on Anti-Spam, direct marketing by telephone and text messages follows similar principles on required consent and opt-out mechanism as set out above. Advertisers are also restricted to make maximum three advertising calls or send a maximum of three advertising text messages to one user within 24 hours unless otherwise agreed with the user.
Further to the above, advertisers are not permitted to make advertising calls or send advertising text messages to users within the Do Not Call list. Advertisers are required to carefully check the Do Not Call list before advertising. Unless otherwise agreed with users, advertisers are only permitted to send advertising text messages from 7:00 am to 10:00 pm every day, and make advertising calls from 8:00 am to 5:00 pm every day.
Advertisers are required to register with the Ministry of Public Security (formerly Ministry of Information and Communications) and obtain from this authority a name identifier code before they can make advertising calls or send advertising text messages.
Conditions for direct marketing by telephone to corporate subscribers (excludes automated calls)
The rules are the same as for individual subscribers.
Exemptions and other issues
There are further requirements in relation to advertising text messages. Particularly, advertising messages must be labelled with [QC] or [AD] at the beginning of the message subject to indicate that it is an advertising text message. Where the advertising text message concerns a chargeable service, the text message must provide information on the fees to be charged. Further, an advertising text message must include a function permitting users to opt-out from receiving advertising text messages.