🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
VN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing11 sources retrieved model claude-sonnet-5 · 2026-08-06

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Vietnam

VN schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 34 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 23 August 2026.

Lead Signal

Vietnam elevated data protection from decree-level regulation to statutory law this cycle. Law No. 91/2025/QH15, the Personal Data Protection Law, was enacted 26 June 2025 and became effective 1 January 2026, with Decree No. 356/2025/ND-CP formally replacing the prior Decree No. 13/2023/ND-CP as the law's implementing instrument. The Ministry of Public Security and the Ministry of Information and Communication are the primary regulatory authorities under the new framework. The law's territorial scope is broad: it applies to Vietnamese agencies, organisations and individuals, to foreign entities operating in Vietnam, and to foreign entities processing the personal data of Vietnamese citizens regardless of where that processing occurs. The most consequential feature of the new law is its penalty framework: Article 8 introduces a tiered structure with fines of up to ten times illicitly gained revenue, a fallback fine of VND 3 billion where gains cannot be quantified, and a specific penalty of up to 5 percent of a corporate violator's prior-year annual revenue for cross-border data-transfer breaches. This is a materially strengthened enforcement posture relative to the prior decree-level regime, and it applies to both domestic and foreign-operating entities within the law's territorial scope. The shift from decree to statutory law is itself analytically significant beyond the specific penalty figures: a law passed by the National Assembly carries materially greater durability and amendment friction than a government decree, meaning Vietnam's data-protection framework is now anchored in primary legislation rather than executive rule-making, a change in the framework's legal foundation as much as in its substantive content.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute now in force, but institutional placement inside a security ministry (not an independent DPA) and reliance on secondary (T2) sourcing for implementing-decree specifics warrant an amber rating pending primary-text verification.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberComprehensive omnibus statute now in force, but institutional placement inside a security ministry (not an independent DPA) and reliance on secondary (T2) sourcing for implementing-decree specifics warrant an amber rating pending primary-text verification.

Sub-modules (5)

Regulator And AuthorityAmber

No independent DPA exists; enforcement is divided between MPS (A05) and MIC, with MPS's cybersecurity department as day-to-day enforcer. The MPS official portal (bocongan.gov.vn) is confirmed live per the injected seed anchor.

Claims (2):

  • Vietnam does not have an independent data protection authority; enforcement power is divided between the Ministry of Public Security and the Ministry of Information and Communications, with day-to-day cyber enforcement handled by the Department of Cybersecurity and High-tech Crime Prevention (A05) within MPS.
  • The Ministry of Public Security maintains its official enforcement/cybersecurity portal at bocongan.gov.vn, which functions as the primary regulator gateway for personal-data-protection enforcement matters in Vietnam.

Act And InstrumentsGreen

PDPL (Law 91/2025/QH15) is the primary statute, in force since 1 Jan 2026, implemented by Decree 356/2025/ND-CP; both replace Decree 13/2023/ND-CP.

Claims (2):

  • The Personal Data Protection Law (Law No. 91/2025/QH15), passed by the National Assembly on 26 June 2025, entered into force on 1 January 2026 and replaced Decree No. 13/2023/ND-CP as Vietnam's primary data-protection instrument.
  • Decree No. 356/2025/ND-CP, issued 31 December 2025 and effective 1 January 2026, implements the PDPL and formally replaces Decree 13/2023/ND-CP as the main implementing instrument.

Material ScopeGreen

PDPL classifies data into basic and sensitive personal data, with sensitive data defined broadly (location, login credentials, behavioural monitoring).

Claims (1):

  • The PDPL classifies personal data into 'basic personal data' and 'sensitive personal data', with sensitive data defined broadly to include location data, account log-in details and behavioural/online monitoring data.

Territorial ScopeGreen

Extraterritorial application confirmed: foreign entities processing Vietnamese citizens'/residents' data are covered.

Claims (1):

  • The PDPL applies extraterritorially to foreign agencies, organisations and individuals that process the personal data of Vietnamese citizens or of individuals residing in Vietnam, in addition to domestic entities.

Regulator Registration And FilingAmber

Cross-border transfer risk-assessment filings with the competent domestic authority are required; general registration regime for domestic processing not independently confirmed beyond transfer-filing context.

Claims (1):

  • Cross-border transfer of personal data under the PDPL/Decree 356 regime requires prescriptive risk/impact-assessment filings with the competent domestic authority in addition to contractual safeguards.

Key findings (1)

  • PDPL (Law 91/2025/QH15) and Decree 356/2025/ND-CP superseded Decree 13/2023/ND-CP effective 1 January 2026; enforcement remains split MPS(A05)/MIC absent an independent DPA. — source on file
Category narrative141 words

Vietnam's data-protection regime was fundamentally superseded during the seed-anchor window: the injected seed anchored on Decree 13/2023/ND-CP (PDPD), but research confirms Vietnam's National Assembly passed a standalone Personal Data Protection Law (PDPL, Law No. 91/2025/QH15) on 26 June 2025, which entered into force 1 January 2026 and replaced Decree 13 as the primary statute. Implementing Decree No. 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) operationalises the PDPL and formally supersedes Decree 13. There remains no independent EU-model DPA; enforcement is split between the Ministry of Public Security (MPS) -- principally its Department of Cybersecurity and High-tech Crime Prevention (A05) -- and the Ministry of Information and Communications (MIC), with the Ministry of National Defense playing a role in some contexts. This confirms the seed's disambiguation note: the enforcement body is security-oriented and ministry-embedded rather than an independent supervisory authority.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. UncertainIAPP — Vietnam does not have an independent data protection authority; enforcement power is divided between the Ministry of Public Security and the Ministry of Information and Communications, with day-to-day cyber enforcement handled by the Department of Cybersecurity and High-tech Crime Prevention (A05) within MPS.observed
  2. UncertainGovernment of Vietnam — The Ministry of Public Security maintains its official enforcement/cybersecurity portal at bocongan.gov.vn, which functions as the primary regulator gateway for personal-data-protection enforcement matters in Vietnam.observed
  3. UncertainOneTrust DataGuidance — The Personal Data Protection Law (Law No. 91/2025/QH15), passed by the National Assembly on 26 June 2025, entered into force on 1 January 2026 and replaced Decree No. 13/2023/ND-CP as Vietnam's primary data-protection instrument.observed
  4. UncertainOneTrust DataGuidance — Decree No. 356/2025/ND-CP, issued 31 December 2025 and effective 1 January 2026, implements the PDPL and formally replaces Decree 13/2023/ND-CP as the main implementing instrument.observed
  5. UncertainIAPP — The PDPL classifies personal data into 'basic personal data' and 'sensitive personal data', with sensitive data defined broadly to include location data, account log-in details and behavioural/online monitoring data.observed
  6. UncertainOneTrust DataGuidance — The PDPL applies extraterritorially to foreign agencies, organisations and individuals that process the personal data of Vietnamese citizens or of individuals residing in Vietnam, in addition to domestic entities.observed
  7. UncertainIAPP — Cross-border transfer of personal data under the PDPL/Decree 356 regime requires prescriptive risk/impact-assessment filings with the competent domestic authority in addition to contractual safeguards.observed

#

Consent and special-category treatment are well evidenced; lawful-basis enumeration and anonymisation/pseudonymisation safe-harbour detail are thin and carry Uncertain confidence.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberConsent and special-category treatment are well evidenced; lawful-basis enumeration and anonymisation/pseudonymisation safe-harbour detail are thin and carry Uncertain confidence.

Sub-modules (4)

Lawful BasesRed

Only the predecessor Decree 13 no-consent exceptions (e.g., emergencies) were located; whether the PDPL/Decree 356 regime retains an identical or expanded lawful-basis list has not been confirmed from primary text. absent_field_provenance: searched 'Vietnam PDPL lawful bases processing without consent'.

Claims (1):

  • Under the predecessor Decree 13/2023/ND-CP framework, processing without consent was permitted in defined circumstances such as emergencies; whether the PDPL/Decree 356 regime retains an identical exception list has not been independently verified from primary text.

Special CategoriesGreen

Sensitive personal data receives materially stronger protection obligations than basic personal data.

Claims (1):

  • Sensitive personal data (including location, account log-in and behavioural-monitoring data) receives materially stronger protection obligations than basic personal data under the PDPL/Decree 356 framework.

Pseudonymisation And AnonymisationAmber

The PDPL's definition of personal data excludes de-identified data, implying an anonymisation carve-out, but no detailed pseudonymisation safe-harbour criteria were located.

Claims (1):

  • The PDPL defines 'personal data' to exclude de-identified data, establishing an implicit anonymisation carve-out from the law's scope.
Category narrative52 words

The PDPL tightens consent standards relative to Decree 13 and imposes materially heavier obligations for sensitive personal data. A full GDPR Art.6-style enumeration of lawful bases distinct from consent, and a detailed pseudonymisation safe-harbour, were not independently verifiable from the secondary sources reviewed (primary Vietnamese-language text not directly retrievable in this run).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Under the predecessor Decree 13/2023/ND-CP framework, processing without consent was permitted in defined circumstances such as emergencies; whether the PDPL/Decree 356 regime retains an identical exception list has not been independently verified from primary text.observed
  2. UncertainIAPP — The PDPL tightens consent requirements relative to the 2023 Decree, requiring more specific and informed consent standards for personal-data processing.observed
  3. UncertainIAPP — Sensitive personal data (including location, account log-in and behavioural-monitoring data) receives materially stronger protection obligations than basic personal data under the PDPL/Decree 356 framework.observed
  4. UncertainOneTrust DataGuidance — The PDPL defines 'personal data' to exclude de-identified data, establishing an implicit anonymisation carve-out from the law's scope.observed

#

Core access/rectification/erasure rights are well evidenced; portability, restriction/objection, and response-deadline specifics are thin.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberCore access/rectification/erasure rights are well evidenced; portability, restriction/objection, and response-deadline specifics are thin.

Sub-modules (5)

Access RightGreen

PDPL establishes rights to be informed and to access personal data.

Claims (1):

  • The PDPL establishes a diversified set of data-subject rights including the right to be informed and the right of access to one's personal data.

Rectification And ErasureGreen

PDPL grants correction and deletion rights, with Decree 356 detailing request procedures.

Claims (1):

  • The PDPL grants data subjects the right to correct and the right to delete (erase) their personal data, with Decree 356 prescribing detailed procedures for responding to such requests, including data protection impact assessments.

Restriction And ObjectionRed

No standalone restriction-of-processing or objection/profiling opt-out right was independently confirmed in the secondary sources reviewed. absent_field_provenance: searched 'Vietnam PDPL right to restrict processing object profiling'.

Data PortabilityAmber

Decree 13 (predecessor) recognised portability; retention under the PDPL/Decree 356 text is unconfirmed.

Claims (1):

  • The predecessor Decree 13/2023/ND-CP recognised a data-portability right for data subjects; no independent verification was found confirming portability is retained expressly under the PDPL/Decree 356 text.

Deadlines And Response WindowsRed

No specific statutory subject-access-request response deadline (distinct from the 72-hour breach-notification window) was located. absent_field_provenance: searched 'Vietnam PDPL data subject request response deadline days'.

Category narrative47 words

The PDPL establishes a diversified set of data-subject rights (to be informed, access, correction, deletion), with Decree 356 prescribing detailed request-handling procedures. Restriction/objection rights and an explicit statutory response-deadline window were not independently confirmed; portability's retention under the new regime (versus the predecessor Decree 13) is Uncertain.

Sources and claims (3)
  1. UncertainIAPP — The PDPL establishes a diversified set of data-subject rights including the right to be informed and the right of access to one's personal data.observed
  2. UncertainIAPP — The PDPL grants data subjects the right to correct and the right to delete (erase) their personal data, with Decree 356 prescribing detailed procedures for responding to such requests, including data protection impact assessments.observed
  3. UncertainOneTrust DataGuidance — The predecessor Decree 13/2023/ND-CP recognised a data-portability right for data subjects; no independent verification was found confirming portability is retained expressly under the PDPL/Decree 356 text.observed

#

DPIA, security and breach-notification obligations are reasonably evidenced (Probable/Confirmed); DPO thresholds, joint-controller rules and retention limits are unconfirmed gaps.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberDPIA, security and breach-notification obligations are reasonably evidenced (Probable/Confirmed); DPO thresholds, joint-controller rules and retention limits are unconfirmed gaps.

Sub-modules (7)

Accountability And DpiaGreen

Decree 356 prescribes DPIA procedures; small business/start-up/micro-enterprise exemption option for five years.

Claims (1):

  • Decree 356/2025/ND-CP prescribes detailed procedures for data protection impact assessments (DPIAs), and small businesses, start-ups, business households and micro-enterprises may elect whether to implement DPIA-preparation obligations for a five-year grace period.

Dpo RequirementsRed

No specific DPO appointment threshold or independence requirement was located. absent_field_provenance: searched 'Vietnam PDPL DPO appointment threshold data protection officer'.

Ropa RequirementsAmber

Decree 356 introduces enhanced reporting forms and audit roles consistent with a records-of-processing style obligation, though not confirmed as a discrete ROPA mandate.

Claims (1):

  • Decree 356 introduces enhanced administrative and enforcement tooling, including new reporting forms, audit roles and clarified controller/processor responsibilities, consistent with a records-of-processing style obligation.

Joint Controller ArrangementsRed

No joint-controller-specific allocation-of-liability rules were located. absent_field_provenance: searched 'Vietnam PDPL joint controller liability'.

Security MeasuresAmber

General technical/organisational security obligations apply under the PDPL/Decree 356 regime, reinforced by sector-specific circulars (e.g., SBV biometric/anti-tampering rules).

Claims (1):

  • Under the PDPL/Decree 356 regime, controllers and processors must implement appropriate technical and organisational security measures to protect personal data, with sectoral regulators elaborating specific technical baselines.

Breach NotificationGreen

Decree 356 requires notification of breach incidents to the competent authority within 72 hours of detection.

Claims (1):

  • Decree 356/2025/ND-CP requires controllers to notify the competent authority of personal-data breach incidents within 72 hours of detection.

Retention And DisposalRed

No explicit statutory retention-period ceiling or disposal-duty detail was located. absent_field_provenance: searched 'Vietnam PDPL data retention period disposal'.

Category narrative42 words

Decree 356 prescribes DPIA procedures with a five-year opt-in grace period for small businesses/start-ups/micro-enterprises, enhanced reporting/audit tooling consistent with a ROPA-style obligation, general security-of-processing duties, and a 72-hour breach-notification-to-authority window. DPO appointment thresholds, joint-controller-specific rules, and retention/disposal ceilings were not independently confirmed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. UncertainOneTrust DataGuidance — Decree 356/2025/ND-CP prescribes detailed procedures for data protection impact assessments (DPIAs), and small businesses, start-ups, business households and micro-enterprises may elect whether to implement DPIA-preparation obligations for a five-year grace period.observed
  2. UncertainIAPP — Decree 356 introduces enhanced administrative and enforcement tooling, including new reporting forms, audit roles and clarified controller/processor responsibilities, consistent with a records-of-processing style obligation.observed
  3. UncertainIAPP — Under the PDPL/Decree 356 regime, controllers and processors must implement appropriate technical and organisational security measures to protect personal data, with sectoral regulators elaborating specific technical baselines.observed
  4. UncertainIAPP — Decree 356/2025/ND-CP requires controllers to notify the competent authority of personal-data breach incidents within 72 hours of detection.observed

#

Transfer-mechanism and localisation obligations are well evidenced (Confirmed/Probable); adequacy received/granted are confirmed absent, which is itself a legitimate red-flagged finding.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15), Decree No. 356/2025/ND-CP, and Decree No. 53/2022/ND-CP (Cybersecurity Law implementing decree)
Traffic-light rationale — AmberTransfer-mechanism and localisation obligations are well evidenced (Confirmed/Probable); adequacy received/granted are confirmed absent, which is itself a legitimate red-flagged finding.

Sub-modules (6)

Transfer MechanismsGreen

Transfers permitted under PDPL Art.19(1) enumerated conditions.

Claims (1):

  • Cross-border transfers of personal data under the PDPL are permitted only under specified conditions, including data-subject consent, intra-organisational transfers, transfers to processors, and transfers requested by competent state agencies (PDPL Art.19(1)).

Adequacy ReceivedRed

No evidence Vietnam has received an adequacy decision from any other regime (e.g., EU). absent_field_provenance: searched 'Vietnam adequacy decision EU GDPR received'.

Adequacy GrantedRed

No evidence Vietnam has issued formal adequacy-style determinations toward other jurisdictions; the regime instead relies on case-by-case contractual/consent mechanisms. absent_field_provenance: searched 'Vietnam PDPL adequacy list granted countries'.

Sccs And BcrsAmber

The transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism; no BCR-equivalent instrument confirmed.

Claims (1):

  • The PDPL/Decree 356 cross-border transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism.

Transfer Impact AssessmentAmber

A risk/impact assessment must be filed with the competent domestic authority prior to cross-border transfer.

Claims (1):

  • Cross-border personal-data transfers require a risk/impact assessment to be filed with the competent domestic authority prior to transfer.

Data LocalisationAmber

Decree 53/2022/ND-CP maintains data-localisation duties for certain service providers, and MPS/A05 guidance (per seed) provides the operative interpretation.

Claims (2):

  • Decree 53/2022/ND-CP, issued under the 2018 Cybersecurity Law, continues to impose data-localisation requirements on certain service providers notwithstanding the PDPL's separate cross-border transfer regime.
  • MPS/A05 operative guidance interprets the personal-data-protection framework as retaining data-localisation obligations for specified categories of service providers.
Category narrative75 words

Cross-border transfers are permitted only under enumerated conditions (consent, intra-organisational transfer, transfer to a processor, transfer requested by a competent state agency -- PDPL Art.19(1)), backed by binding contractual protections and a mandatory transfer risk/impact assessment filed with the domestic authority. Separately, Decree 53/2022/ND-CP (under the 2018 Cybersecurity Law) continues to impose data-localisation duties on certain service providers, confirming the seed's CAUTION flag. No evidence of Vietnam receiving or granting formal adequacy-style decisions was found.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — Cross-border transfers of personal data under the PDPL are permitted only under specified conditions, including data-subject consent, intra-organisational transfers, transfers to processors, and transfers requested by competent state agencies (PDPL Art.19(1)).observed
  2. UncertainIAPP — The PDPL/Decree 356 cross-border transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism.observed
  3. UncertainIAPP — Cross-border personal-data transfers require a risk/impact assessment to be filed with the competent domestic authority prior to transfer.observed
  4. UncertainOneTrust DataGuidance — Decree 53/2022/ND-CP, issued under the 2018 Cybersecurity Law, continues to impose data-localisation requirements on certain service providers notwithstanding the PDPL's separate cross-border transfer regime.observed
  5. UncertainGovernment of Vietnam — MPS/A05 operative guidance interprets the personal-data-protection framework as retaining data-localisation obligations for specified categories of service providers.observed

#

Financial, telecom and education overlays are reasonably evidenced; health/employment/credit/insurance sub-modules carry explicit evidentiary gaps.

Primary frameworkSector-specific circulars/decrees layered on the PDPL/Decree 356 baseline (SBV Circular 77/2025/TT-NHNN; MOET Circular 49/2026/TT-BGDDT)
Traffic-light rationale — AmberFinancial, telecom and education overlays are reasonably evidenced; health/employment/credit/insurance sub-modules carry explicit evidentiary gaps.

Sub-modules (7)

Financial Sector OverlayGreen

SBV Circular 77/2025/TT-NHNN imposes mobile-banking security and biometric standards on credit institutions.

Claims (1):

  • The State Bank of Vietnam (SBV) issued Circular 77/2025/TT-NHNN amending online-banking safety rules, requiring credit institutions to deploy anti-tampering safeguards in mobile banking apps from 1 March 2026 and biometric-matching standards (including Presentation Attack Detection meeting ISO 30107 Level 2) from 1 July 2026.

Health Sector OverlayRed

No health-sector-specific data-protection overlay was located. absent_field_provenance: searched 'Vietnam health data protection law HIPAA equivalent 2026'.

Telecoms And EprivacyAmber

Biometric re-authentication and SIM self-authentication rules layer identity-verification duties onto telecom data processing; no dedicated ePrivacy/cookie-consent instrument confirmed.

Claims (1):

  • Vietnam introduced mandatory facial-recognition re-authentication for mobile subscribers changing devices and self-authentication of SIM ownership via the VNeID app, effective 15 April 2026, layering biometric identity-verification duties onto telecom data processing.

Employment DataRed

No employment-specific data-protection code was located. absent_field_provenance: searched 'Vietnam employment data protection code PDPL'.

Credit And ScoringRed

No credit-scoring-specific data rules were located. absent_field_provenance: searched 'Vietnam credit scoring data protection rules'.

EducationAmber

MOET Circular 49/2026/TT-BGDDT regulates technology use in education with data-protection emphasis.

Claims (1):

  • Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT regulating technology use in education, emphasising data protection, interoperability and ethical AI use.

InsuranceRed

No insurance-sector-specific data-protection overlay was located. absent_field_provenance: searched 'Vietnam insurance sector data protection rules PDPL'.

Category narrative64 words

Confirmed sectoral overlays: (i) financial sector -- SBV Circular 77/2025/TT-NHNN imposing mobile-banking anti-tampering and biometric-matching (PAD/ISO 30107 Level 2) standards on credit institutions with staged 2026 effective dates; (ii) telecoms -- mandatory facial-recognition re-authentication and VNeID SIM self-authentication; (iii) education -- MOET Circular No. 49/2026/TT-BGDDT on technology use in education emphasising data protection. Health, employment, credit-scoring and insurance sectoral overlays were not independently confirmed.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — The State Bank of Vietnam (SBV) issued Circular 77/2025/TT-NHNN amending online-banking safety rules, requiring credit institutions to deploy anti-tampering safeguards in mobile banking apps from 1 March 2026 and biometric-matching standards (including Presentation Attack Detection meeting ISO 30107 Level 2) from 1 July 2026.observed
  2. UncertainOneTrust DataGuidance — Vietnam introduced mandatory facial-recognition re-authentication for mobile subscribers changing devices and self-authentication of SIM ownership via the VNeID app, effective 15 April 2026, layering biometric identity-verification duties onto telecom data processing.observed
  3. UncertainOneTrust DataGuidance — Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT regulating technology use in education, emphasising data protection, interoperability and ethical AI use.observed

#

Only direct-marketing restriction is evidenced; five of six sub-modules carry explicit absent_field_provenance gaps -- consistent with Vietnam having no dedicated adtech/ePrivacy instrument distinct from the general PDPL.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) -- general marketing/advertising restriction only; no dedicated adtech instrument identified
Traffic-light rationale — RedOnly direct-marketing restriction is evidenced; five of six sub-modules carry explicit absent_field_provenance gaps -- consistent with Vietnam having no dedicated adtech/ePrivacy instrument distinct from the general PDPL.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime distinct from general PDPL consent rules was located. absent_field_provenance: searched 'Vietnam cookie consent law ePrivacy equivalent'.

Dark PatternsRed

No dark-pattern-specific prohibition was located. absent_field_provenance: searched 'Vietnam dark patterns consent law PDPL'.

Opt Out SignalsRed

No recognition of technical opt-out signals (e.g., Global Privacy Control) was located. absent_field_provenance: searched 'Vietnam Global Privacy Control opt-out signal recognition'.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rules were located. absent_field_provenance: searched 'Vietnam data clean room rules PDPL'.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising concept was located. absent_field_provenance: searched 'Vietnam cross-context advertising data sale PDPL'.

Direct MarketingAmber

PDPL restricts processing for marketing/advertising purposes and prohibits unauthorised trading of personal information.

Claims (1):

  • The PDPL imposes restrictions on personal-data processing for marketing and advertising purposes, alongside its general prohibition on the purchase and sale of personal information.
Category narrative41 words

The PDPL restricts personal-data processing for marketing/advertising purposes and prohibits unauthorised buying/selling of personal information. No dedicated cookie/ePrivacy-style consent regime, dark-pattern prohibition, opt-out-signal (e.g., GPC) recognition, clean-room/DCR framework, or cross-context-advertising ('sale'/'share') concept equivalent to CPRA was located in the sources reviewed.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — The PDPL imposes restrictions on personal-data processing for marketing and advertising purposes, alongside its general prohibition on the purchase and sale of personal information.observed

#

AI-law and biometric evidence is strong (Confirmed/Probable); Art.22-equivalent profiling/ADM transparency, genetic data, and surveillance carve-outs remain unconfirmed gaps.

Primary frameworkLaw on Artificial Intelligence (effective 1 March 2026) and Decree No. 142/2026/ND-CP; PDPL/Decree 356 for general data-processing baseline
Traffic-light rationale — AmberAI-law and biometric evidence is strong (Confirmed/Probable); Art.22-equivalent profiling/ADM transparency, genetic data, and surveillance carve-outs remain unconfirmed gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Art.22-equivalent profiling restriction was independently confirmed. absent_field_provenance: searched 'Vietnam PDPL profiling restriction automated decision'.

Automated Decision Making TransparencyRed

No ADM transparency/explanation right distinct from general access rights was confirmed. absent_field_provenance: searched 'Vietnam PDPL automated decision making transparency explanation right'.

Ai Risk AssessmentsGreen

AI Law and Decree 142/2026/ND-CP establish risk-based classification and conformity-assessment obligations for AI systems.

Claims (2):

  • Vietnam's first standalone AI Law, adopted December 2025 and effective 1 March 2026, introduces a risk-based classification and conformity-assessment framework for AI systems with concepts similar to the EU AI Act, and supersedes the AI provisions of the Law on Digital Technology Industry (effective 1 January 2026).
  • Decree No. 142/2026/ND-CP mandates AI risk classification and conformity-assessment obligations based on defined risk levels and criteria, implementing the AI Law.

Biometric RegimeGreen

Sector regulators (SBV, telecom authorities) impose specific biometric-verification technical standards.

Claims (1):

  • Sector regulators have imposed specific biometric-verification standards, including SBV-mandated Presentation Attack Detection (PAD) meeting ISO 30107 Level 2 for mobile-banking biometric authentication and mandatory facial-recognition re-authentication for mobile subscribers changing devices.

Genetic DataRed

No genetic-data-specific regime was located. absent_field_provenance: searched 'Vietnam genetic data protection law PDPL'.

State Surveillance CarveoutsRed

No national-security/state-surveillance carve-out detail specific to the PDPL was located. absent_field_provenance: searched 'Vietnam PDPL national security exemption state surveillance carveout'.

Key findings (1)

  • Vietnam's first standalone AI Law and Decree 142/2026/ND-CP introduce an EU-AI-Act-like risk-classification/conformity-assessment regime, effective 1 March 2026. — source on file
Category narrative69 words

Vietnam's first standalone AI Law (adopted December 2025, effective 1 March 2026) introduces an EU-AI-Act-like risk-based classification and conformity-assessment framework, superseding the AI provisions of the Law on Digital Technology Industry. Decree 142/2026/ND-CP further mandates AI risk classification/conformity assessment. Biometric-verification standards are confirmed via SBV mobile-banking rules and telecom facial-recognition re-authentication. Profiling restrictions, ADM transparency rights, genetic-data rules and state-surveillance carve-outs specific to the PDPL were not independently confirmed.

Sources and claims (3)
  1. UncertainIAPP — Vietnam's first standalone AI Law, adopted December 2025 and effective 1 March 2026, introduces a risk-based classification and conformity-assessment framework for AI systems with concepts similar to the EU AI Act, and supersedes the AI provisions of the Law on Digital Technology Industry (effective 1 January 2026).observed
  2. UncertainOneTrust DataGuidance — Decree No. 142/2026/ND-CP mandates AI risk classification and conformity-assessment obligations based on defined risk levels and criteria, implementing the AI Law.observed
  3. UncertainOneTrust DataGuidance — Sector regulators have imposed specific biometric-verification standards, including SBV-mandated Presentation Attack Detection (PAD) meeting ISO 30107 Level 2 for mobile-banking biometric authentication and mandatory facial-recognition re-authentication for mobile subscribers changing devices.observed

#

Only a tangential education-settings signal was found; four of five sub-modules carry explicit absent_field_provenance gaps, warranting escalation to primary Vietnamese-language text.

Traffic-light rationale — RedOnly a tangential education-settings signal was found; four of five sub-modules carry explicit absent_field_provenance gaps, warranting escalation to primary Vietnamese-language text.

Sub-modules (5)

Age VerificationRed

No minimum age-of-consent threshold for data processing was located. absent_field_provenance: searched 'Vietnam PDPL children minors data protection consent parental biometric facial recognition'.

Minor Profiling BansRed

No minor-specific profiling ban was located. absent_field_provenance: searched 'Vietnam PDPL minor profiling ban advertising children'.

Education SettingsAmber

MOET Circular 49/2026/TT-BGDDT regulates technology use in education with a data-protection emphasis, relevant to minors' data in schools, though it is not itself a minors-specific data-protection statute.

Claims (1):

  • Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT to regulate technology use in education settings, with an emphasis on data protection, interoperability and ethical AI use, relevant to the processing of minors' data in schools.

Dependent AdultsRed

No provisions specific to dependent adults (elderly, mentally incapacitated) were located. absent_field_provenance: searched 'Vietnam data protection dependent adults elderly incapacitated'.

Category narrative55 words

Despite targeted searches, no PDPL/Decree 356 provisions specifying a minimum age of consent, a parental-consent mechanism, or minor-specific profiling bans were located in the secondary sources reviewed. A confirmed education-sector circular (MOET Circular 49/2026/TT-BGDDT) touches technology use in schools but does not itself establish a discrete minors' data-protection regime. Dependent-adult (elderly/incapacitated) protections were not located.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT to regulate technology use in education settings, with an emphasis on data protection, interoperability and ethical AI use, relevant to the processing of minors' data in schools.observed

#

Penalty framework is well evidenced (Confirmed); enforcement track record, funding/capacity, collective redress and private right of action are unconfirmed gaps consistent with the regime's short operating history.

Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberPenalty framework is well evidenced (Confirmed); enforcement track record, funding/capacity, collective redress and private right of action are unconfirmed gaps consistent with the regime's short operating history.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

PDPL sets tiered administrative/criminal penalties for violations.

Claims (1):

  • The PDPL provides for administrative and criminal penalties for violations, including fines of up to ten times the illicit gains for unlawful trading of personal data, up to 5% of the offending entity's prior-year revenue for cross-border transfer violations, and fines of up to VND 3 billion for other breaches.

Enforcement Activity IndexAmber

No significant published enforcement decisions were located; regime newly in force since 1 Jan 2026.

Claims (1):

  • As the PDPL/Decree 356 regime has been in force only since 1 January 2026, no significant published enforcement decisions or fines against controllers were located in the sources reviewed as of the research date.

Regulator Funding And CapacityRed

No data on MPS/A05 staffing or budget for PDPL enforcement was located. absent_field_provenance: searched 'Vietnam MPS A05 cybersecurity department budget headcount 2026'.

Collective Redress And Class ActionsRed

No dedicated collective-redress/class-action mechanism for data-protection claims was identified. absent_field_provenance: searched 'Vietnam class action data protection collective redress civil procedure'.

Private Right Of ActionRed

Not confirmed whether the PDPL provides a direct private right of action distinct from administrative/criminal enforcement. absent_field_provenance: searched 'Vietnam PDPL private right of action civil suit data subject'.

Recent Developments 180DAmber

Within 180 days preceding this research, Vietnam's AI Law took effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification was issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceeded through staged 2026 effective dates, alongside continued PDPL/Decree 356 implementation bedding-in.

Claims (1):

  • Within the 180 days preceding this research (August 2026), Vietnam's regulatory landscape saw the AI Law take effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceed through staged effective dates into July 2026, alongside continued PDPL/Decree 356 implementation.
Category narrative73 words

The PDPL sets tiered administrative/criminal penalties (up to 10x illicit gains for unlawful data trading; up to 5% of prior-year revenue for cross-border violations; up to VND 3 billion for other breaches). Because the regime only entered force 1 January 2026, no significant published enforcement decisions were located as of the August 2026 research date. Regulator funding/capacity data, collective-redress mechanisms, and a private right of action distinct from administrative enforcement were not confirmed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. UncertainOneTrust DataGuidance — The PDPL provides for administrative and criminal penalties for violations, including fines of up to ten times the illicit gains for unlawful trading of personal data, up to 5% of the offending entity's prior-year revenue for cross-border transfer violations, and fines of up to VND 3 billion for other breaches.observed
  2. UncertainOneTrust DataGuidance — As the PDPL/Decree 356 regime has been in force only since 1 January 2026, no significant published enforcement decisions or fines against controllers were located in the sources reviewed as of the research date.observed
  3. UncertainIAPP — Within the 180 days preceding this research (August 2026), Vietnam's regulatory landscape saw the AI Law take effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceed through staged effective dates into July 2026, alongside continued PDPL/Decree 356 implementation.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct52.94
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Vietnam
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (34 category placement(s)), 17 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Module 1 (regulator_and_framework), module 5's transfer/localisation core, module 6's financial overlay, and module 8's AI-law core rest on at least one T1-adjacent anchor (bocongan.gov.vn per seed) plus multiple corroborating T2 sources (DataGuidance, IAPP), and are the strongest-evidenced areas. Modules 3 (data_subject_rights) and 4 (controller_processor_duties) are moderately evidenced via T2 secondary summaries but lack DPO-threshold, retention-limit, and full deadline specifics. Modules 7 (adtech_and_commercial_privacy), 9 (children_and_vulnerable_groups), and several sectoral sub-modules (health, employment, credit, insurance) rely entirely on absent_field_provenance disclosures -- no T1/T2/T3 evidence located despite targeted searches. Critically, the injected seed anchor (Decree 13/2023/ND-CP as the operative statute) was found to be superseded: the PDPL (Law 91/2025/QH15) and Decree 356/2025/ND-CP now govern, entering force 1 January 2026 -- this supersession is the single most material finding of this run and should be flagged upstream.

Unresolved questions (9):

  • Does the PDPL/Decree 356 regime retain, expand, or replace the Decree-13-era lawful-basis exceptions (e.g., emergency processing without consent)?
  • Is there a codified DPO appointment threshold and independence requirement under Decree 356?
  • Is data portability retained as an express right under the PDPL, or was it dropped relative to Decree 13?
  • What is the statutory SAR/response-window deadline (distinct from the 72-hour breach-notification window)?
  • Has Vietnam received or granted any formal adequacy-equivalent determination with any other jurisdiction?
  • What is the minimum age of consent and parental-consent mechanism (if any) under the PDPL for minors' data?
  • Has any enforcement action, fine, or published decision been issued under the PDPL/Decree 356 regime since 1 January 2026?
  • Does the PDPL provide a private right of action / direct court access for data subjects, distinct from administrative and criminal enforcement?
  • Does the revamped 2025/2026 Cybersecurity Law (effective 1 July 2026) alter the data-localisation scope beyond Decree 53/2022/ND-CP?

Escalate to primary-source review: yes