NEXORA
· 18 min read

Vietnam's Personal Data Protection Law (2025): Full Overview and the Practical Steps Companies Must Take

Attorney and Patent Attorney admitted in Vietnam

NEXORA LAW FIRM, Managing Partner
Attorney admitted in Vietnam
Mediator, Bankruptcy Trustee, Outside Statutory Auditor

Table of Contents
01 - Extraterritorial Scope: Direct Application to Foreign Companies and Individuals
02 - Expanded Definition of "Personal Data": Protection Not Limited to Electronic Information
03 - Cross-Border Transfer of Personal Data: Expanded Scope and New Exceptions
04 - Penalties for Violations of Personal Data Protection: Covering Administrative Sanctions, Criminal Liability, and Civil Damages
05 - Impact Assessment Reports for Personal Data Processing and Cross-Border Transfer: Clarified Preparation Obligations and Update Frequency
06 - Special Protections for Personal Data in the Employment Relationship
07 - Protection of Health-Related Personal Data: Consent and Special Management Now Mandatory
08 - Obligation to Appoint Personal Data Protection Personnel/Department: Applicable to All Organizations
09 - Exemption/Grace Period Regime for Small Businesses and Startups (Article 38)
10 - Special Provisions on Personal Data Protection in Specific Sectors: Finance, Social Media, AI, Blockchain, etc. (Articles 27–30)

A Vietnamese attorney provides a thorough explanation of Vietnam's Personal Data Protection Law, which takes effect in 2026 — covering the extension of scope to overseas operators, new rules on cross-border transfer, the obligation to prepare impact assessments, and strengthened protection of labor and health data — organizing the 10 key points of reform and practical responses that Japanese-affiliated companies should confirm now. Penalties for violations are also extremely severe, reaching up to VND 3,000,000,000. NEXORA LAWFIRM has extensive experience supporting Japanese-affiliated companies in building compliance systems in Vietnam, formulating data protection regulations, establishing internal whistleblowing systems, and appointing DPOs (Data Protection Officers), and provides comprehensive legal and practical support for the transition to the new 2025 law.

On June 26, 2025, Vietnam's National Assembly passed a new Law on Personal Data Protection (Luật Bảo vệ Dữ liệu Cá nhân). This law formally takes effect on January 1, 2026, and will replace the existing Decree No. 13/2023/ND-CP (Nghị định số 13) as the comprehensive legal framework governing the collection, use, management, and sharing of personal information in Vietnam.

This article organizes the differences between the new law and the former decree, and explains the points that foreign-invested companies in particular should note, together with the direction of practical response.

01 - Extraterritorial Scope: Direct Application to Foreign Companies and Individuals

Under the Personal Data Protection Law 2025, the law's application is expressly extended to cover not only organizations, institutions, and individuals within Vietnam, but also overseas operators and individuals. This provision is intended both to strengthen data protection within Vietnam and to respond to the modern reality in which cross-border data transactions and cloud usage have become commonplace.

Which overseas organizations and individuals are covered?

Any foreign institution, company, or individual that meets either of the following conditions will be subject to this law, even if it has no establishment in Vietnam.

Where the entity is directly involved in processing the personal data of individuals holding Vietnamese nationality
 (for example, where a Japanese company's head office processes the data of its Vietnamese national employees)
Where the entity is involved in processing the personal data of a "person of Vietnamese origin" who resides in Vietnam, whose nationality has not yet been determined, but who has obtained identification documents

02 - Expanded Definition of "Personal Data": Protection Not Limited to Electronic Information

Under the 2025 law, "personal data" is defined as follows (Article 2(1)):

"Digital data, or information in any other form, that identifies or assists in identifying a specific individual."

This can be interpreted as meaning that not only digital information (such as electronic files or cloud data) but also personal information contained in paper documents, audio recordings, video, other physical media, or data in unspecified form is all included within the scope of protection.

03 - Cross-Border Transfer of Personal Data: Expanded Scope and New Exceptions

1. Under the Personal Data Protection Law 2025, the previous term "transfer of personal data overseas" (Chuyển dữ liệu cá nhân ra nước ngoài) has been replaced with the broader concept of "cross-border transfer of personal data" (Chuyển dữ liệu cá nhân xuyên biên giới).

2. Decree No. 13 limited the scope of overseas transfer to "the personal data of Vietnamese citizens," meaning that transferring the data of foreign nationals overseas was not subject to regulations such as the assessment obligation. However, under the Personal Data Protection Law 2025, the phrase "Vietnamese citizen" has been removed, and all "personal data" is now covered by the protections (Article 20(1)). As a result, even where the data of a foreign national residing in Vietnam is transmitted overseas, an obligation such as submitting an impact assessment report will arise.

For example, where a Vietnamese local entity employs a foreign national and transmits that employee's personal information to its (foreign) head office, this would be treated as a "cross-border transfer" requiring submission of an impact assessment report.

3. Exceptions to the Assessment Obligation (Article 20(6))

Under the Personal Data Protection Law 2025, it is expressly provided that the obligation to submit an impact assessment report is waived in certain specified circumstances. Representative examples include:

Where a company stores its own employees' data on a cloud service (Google Cloud, Microsoft Azure, AWS, etc.)
Where the data subject transmits their own personal data overseas of their own volition

These exceptions are intended to accommodate common practical scenarios, and mean that transfers via cloud usage or self-initiated transmission by the data subject will not trigger an obligation to prepare an impact assessment report.

Practical Points to Note

That said, the specific conditions and implementation procedures for these exceptions are expected to be set out in decrees and circulars to be issued in the future. Foreign-invested companies, and Japanese-affiliated companies with global operations in particular, routinely engage in cloud usage and data sharing with their parent company, and should continue to monitor developments in the implementing legislation closely.

04 - Penalties for Violations of Personal Data Protection: Covering Administrative Sanctions, Criminal Liability, and Civil Damages

Under Decree No. 13, the forms of sanction for violations of personal data protection — "disciplinary action, administrative sanctions, criminal liability" — were provided for, but the specific violations and penalty levels were not clearly specified (Article 4).

Under the Personal Data Protection Law 2025, this point has been clarified, and the following three forms of sanction are expressly set out in the law:

① Administrative sanctions (administrative fines)

② Criminal liability (prosecution under the Penal Code)

③ Civil liability for damages (under the Civil Code)

The specific sanctions applicable to each type of violation are expected to be set out in decrees and circulars to be promulgated in the future.

Upper and Lower Limits on Administrative Fines Also Clarified (Article 8)

Of particular note is that, for administrative fines, both the minimum and maximum amounts have now been set out in the law itself. This is expected to eliminate the previously ambiguous enforcement practice and to improve the transparency and predictability of penalties imposed on companies and individuals.

For example:

Where personal data is disclosed to a third party without the data subject's consent
Where a data breach occurs due to a failure to implement protective measures
Where a cross-border transfer impact assessment report is not submitted, or a false report is submitted

Serious violations of this kind will inevitably attract a fine of at least a specified amount.

For companies, this means that "the era in which the mere absence of an adequate management system is itself treated as a risk — regardless of intent or negligence" has arrived. Establishing internal rules and training employees should be reconstructed not merely as a preventive measure, but as a legal compliance obligation.

Under the Personal Data Protection Law 2025, sanctions for violations of personal data protection are institutionalized through the following three legal mechanisms:

① Pursuit of Criminal Liability

Serious violations may be subject to criminal prosecution (e.g., intentional trading of information, large-scale leaks, etc.).

② Damages

Where the data subject suffers loss, monetary compensation liability arises under the Civil Code.

③ Administrative Sanctions

Depending on the nature of the violation, fines of the following amounts apply:

Violation

Range of Fines

Trading in personal data

Minimum VND 3,000,000,000, up to 10 times the illegal proceeds

Violations relating to cross-border transfer

Minimum VND 3,000,000,000, up to 5% of the previous year's revenue

Other violations

Fine of up to VND 3,000,000,000

In this way, the treatment of violations is now clearly categorized by type, and this reflects the establishment, for the first time in Vietnam's legal history, of an unprecedentedly robust sanctions framework.

05 - Impact Assessment Reports for Personal Data Processing and Cross-Border Transfer: Clarified Preparation Obligations and Update Frequency

Under the Personal Data Protection Law 2025, rules on the preparation and updating of Data Protection Impact Assessments (DPIAs) have been put in place to clarify companies' data protection responsibilities.

① Initial submission is required only once

② Under Articles 20 and 21, the following assessment reports need only be prepared once, at the time the company is established or commences business:

The impact assessment report on personal data processing
The impact assessment report on cross-border transfer of personal data

③ Circumstances triggering a semi-annual update obligation

Under Decree No. 13, there were provisions on the frequency of updating or reporting the assessment that were unclear or impractical to operate (e.g., an obligation to update within 10 days).
In response, the new law (Article 22) requires the assessment report to be updated in the following circumstances:
Periodic updates every six months (where there have been changes)
Immediate updates upon the occurrence of significant changes such as the following:
Corporate restructuring, merger, or split
A change in the service provider handling data protection
A change in the scope of data handled in connection with the company's registered business activities (industry, products, or services)

Accordingly, updating the assessment report should not be treated as a mere formality, but as a substantive part of building the necessary systems and complying with the law.

Practical Points and Risk of Violation

If a company overlooks the changes described above and fails to update its assessment report, this may be regarded, during an administrative inspection, as an "incomplete assessment report," potentially subjecting the company to sanctions such as fines, corrective guidance, or a temporary suspension of business.

Accordingly, companies should:

Build an internal process to collect information on changes from each department
Strengthen coordination between IT and legal functions to track changes in external services or systems
Obtain advice from lawyers or consultants as needed to review the assessment report on an ongoing basis

Through such measures, companies are required to build a planned and continuous data protection system.

06 - Special Protections for Personal Data in the Employment Relationship

Under the Personal Data Protection Law 2025 (Article 25), clear provisions have, for the first time, been established regarding the handling of personal data in connection with recruitment activities and the performance of labor contracts. Under this provision, employers (whether corporations or individual business owners) must pay attention to the following points.

【Key Obligations】

Information that may be collected is limited to what is necessary for recruitment purposes, and information collected may not be used for any purpose other than the recruitment purpose or another purpose consented to
Personal data of applicants who were not hired must be deleted (except where explicit consent has been given)
On termination of a labor contract, an employee's personal data must be deleted (except where retention is agreed separately or required by law)

Common Compliance Risks Seen in Practice

The following practices are commonly observed in actual corporate activity, but are likely to be regarded as violations of the law going forward:

Obtaining and retaining private information such as social media accounts (Facebook, Instagram, etc.) at the time of recruitment
Unilaterally retaining the information of unsuccessful applicants as "future candidates," at the company's own discretion
Continuing to hold the personal information of former employees within the company without explicit consent or a basis for retention

Absent the individual's consent, such practices may constitute use and retention of personal data beyond the stated purpose, and may become subject to administrative sanctions.

Recommended Measures: Reviewing Internal Systems and Preparing Documentation

To build a compliance system, companies should implement measures such as the following.

Review the entire recruitment and labor process (recruitment, interviews, employment contracts, resignation)
Obtain prior consent forms from applicants regarding the handling of their personal information
Set out data retention/deletion rules explicitly in employment contracts
Establish internal rules on the handling of former employees' data (retention periods, deletion procedures, etc.)

Failure to establish such systems could, in the event of a data breach, result in significant legal liability and reputational damage for the company.

07 - Protection of Health-Related Personal Data: Consent and Special Management Now Mandatory

Article 26 of the Personal Data Protection Law 2025 newly establishes special protections for health information. This is a new point that did not exist under the former Decree No. 13.

Under this provision, the following obligations arise when handling information such as an individual's health condition, diagnostic records, or health checkup results:

Explicit consent from the data subject is required
In addition, because this information falls within "sensitive personal data," more rigorous protective measures than those for ordinary personal data must be implemented

7.1. Practical Impact on Foreign-Invested and General Companies

This provision has a significant bearing on the following kinds of health-information handling that occur when a company recruits, manages, and evaluates its employees.

① Health checkup certificates requested at the time of hiring

② Results of periodic health checkups during employment

③ Records relating to occupational physician consultations and mental health matters

Because this information is legally considered "sensitive information," companies must establish a rigorous management system covering every stage of collection, storage, and sharing.

7.2. Method of Obtaining Consent and Practical Points

It is recommended that consent be obtained from the employee through one of the following methods:

① Preparing a separate consent form specifically for the handling of health information and obtaining a signature

② Or, incorporating explicit consent provisions into the labor contract or probationary contract

In either case, the purpose of use, retention period, and whether the information will be shared with third parties should be specifically stated.

7.3. Enhanced Technical and Organizational Security Measures Are Also Essential

Because a leak of health data carries a high risk of serious privacy infringement and loss of corporate trust, companies are required to implement the following kinds of advanced measures.

08 - Obligation to Appoint Personal Data Protection Personnel/Department: Applicable to All Organizations

Under Decree No. 13, the appointment of personnel or a department responsible for personal data protection was required only "where sensitive data is processed." In addition, there was no specific provision on the qualifications or competency required of the person appointed (Articles 28 and 30).

By contrast, under the Personal Data Protection Law 2025 (Article 33(2)), all companies and organizations are now obligated to designate personnel or a department for personal data protection.

Specifically:

"An organization must appoint personnel or a department with sufficient competence in personal data protection, or outsource this function to an external specialist provider."

All Organizations Are Covered, Regardless of the Type of Data Handled

Under this provision, even organizations handling only basic personal data are now required to build a protection system.

Regardless of whether sensitive data is involved, organizations must either internally appoint personnel or a department, or outsource the function externally.

The Specific Requirements for "Sufficient Competence" Are to Be Set Out in Future Decrees

At present, there is no clear statutory definition of the competence, experience, or qualifications required of the person to be appointed. For this reason, companies should keep a close watch on future circulars and decrees while considering options such as the following.

Internal appointment: selecting from within existing legal, HR, or IT departments
External outsourcing: outsourcing to an external provider with specialist knowledge and practical experience

Practical Advice When Choosing External Outsourcing

For Japanese-affiliated and other foreign-invested companies in particular, since it can be difficult to secure in-house personnel well-versed in Vietnamese law, it is recommended to use an external partner that satisfies conditions such as the following:

A track record in personal information management within Vietnam
Strength in both IT infrastructure and legal matters
The ability to support audits, reporting, and other dealings with the authorities

This reform makes clear that personal data protection is no longer merely a part of "IT security" or "general affairs," but a management issue carrying legal responsibility. Companies must proceed in parallel with establishing internal rules and response processes, in addition to allocating human resources.

09 - Exemption/Grace Period Regime for Small Businesses and Startups (Article 38)

Under Decree No. 13, the appointment of personnel or a department responsible for personal data protection was required only "where sensitive data is processed." In addition, there was no specific provision on the qualifications or competency required of the person appointed (Articles 28 and 30).

Under the Personal Data Protection Law 2025, a regime of exemption or grace periods has been introduced for certain specific obligations relating to personal data protection, applicable to some small businesses and startups (Article 38).

Specifically, for a certain period of five years from the effective date of the law, the following obligations may be exempted or deferred:

The obligation to prepare an impact assessment report on personal data processing
The obligation to report and notify assessment results relating to cross-border transfer
The obligation to appoint a data protection officer
The obligation to periodically update and submit assessment reports to the authorities

Such provisions are considered a measure to ease the legal burden on emerging and small/medium-sized enterprises and to secure a transition period for introducing compliance.

However, the Definition of Eligible Companies Remains Undetermined

As of the time of writing (July 2025), the definitions of "small enterprise," "micro-enterprise," and "startup" are not clearly set out in the text of the law, and it also remains unclear what scale constitutes "a large volume of data subjects."

For this reason, to accurately determine whether one's own company is eligible for an exemption or grace period, it will be necessary to carefully monitor future decrees and circulars (guidance documents).

In this way, Article 38 is an important provision that achieves both "easing the legal burden" and "phased legal compliance" for startups and small/medium-sized enterprises in Vietnam. Companies should prepare their systems in a phased and planned manner, in anticipation of the future expansion of the law's scope of application.

10 - Special Provisions on Personal Data Protection in Specific Sectors: Finance, Social Media, AI, Blockchain, etc. (Articles 27–30)

Under the Personal Data Protection Law 2025, in addition to the general provisions applicable to all companies and organizations, additional, strengthened obligations are set out for specific sectors considered to carry higher risk.

The sectors covered are as follows.

The finance, banking, and credit sector (Article 27)
Social media, online media, and platform operators (Article 29)
Technology sectors such as big data, artificial intelligence (AI), blockchain, and cloud computing (Article 30)

Examples of Additional Obligations Required by Sector

The main requirements common to these sectors are as follows.

Establishing more advanced data encryption and security systems (given the extremely high risk of information leakage)
For AI-based processing, a requirement to classify risk levels and implement graduated protective measures
Providing users with a mechanism to explicitly refuse or manage cookies and tracking information (do-not-track, opt-out, etc.)
Presenting a privacy policy in a form easily understood by users, and publishing the response process in the event of an incident

Practical Points and Recommended Response

For foreign-invested companies and digital service companies in particular, many will fall within the sectors described above, and the following preparations are essential:

Confirming whether the company falls within a covered sector, and identifying the obligations arising under the relevant provisions
Where the matter cannot be handled in-house, building a cooperative relationship with an IT security firm or law firm
Reviewing existing privacy policies and terms of use to ensure compliance with Vietnamese law

The requirements imposed on specific sectors are not mere recommendations but legal obligations, and failure to comply may result in more severe sanctions — including fines and business suspension — than for ordinary companies.

Companies will, going forward, need to position personal data protection in the AI, cloud, fintech, and social media business domains not merely as "information management" but as a core element of strategic risk management.

Conclusion: The Personal Data Protection Law 2025 Is Both a New Legal Responsibility and a Test of Competitiveness for Companies

Vietnam's Personal Data Protection Law, which comes into force in 2025, is an extremely important milestone in establishing the legal framework for personal information protection in the digital economy.

Given its detailed and stringent provisions, together with severe sanctions, this law will require all companies — foreign-invested companies (FDI) in particular — to build a more sophisticated compliance system.

Accordingly, companies are advised to begin the following actions immediately:

A comprehensive review of current personal data processing procedures
Assessing the current level of legal compliance and evaluating risk
Implementing the necessary systems, updating internal rules and contracts, and conducting employee training

Delay in preparation risks not only administrative or criminal liability, but also the loss of international trust and competitiveness. Data protection is now directly linked to corporate value. The time has come for a full-scale response from both a strategic and legal perspective.

【Disclaimer】

Articles on this website are based on the laws and regulations in effect at the time of writing. Where laws or policies subsequently change, the content may no longer be accurate and should be reviewed accordingly.

Content on this website does not constitute legal advice. Please consult a qualified professional for guidance on your specific situation. We accept no responsibility for any direct or indirect damages arising from the use of this website's content without appropriate professional review.

info@nexorawoco.com0985 677 501 (Zalo/LINE: m2H6M8wpfJ)