Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Vietnam
VNschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 34
claims · 17 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Vietnam elevated data protection from decree-level regulation to statutory law this cycle. Law No. 91/2025/QH15, the Personal Data Protection Law, was enacted 26 June 2025 and became effective 1 January 2026, with Decree No. 356/2025/ND-CP formally replacing the prior Decree No. 13/2023/ND-CP as the law's implementing instrument. The Ministry of Public Security and the Ministry of Information and Communication are the primary regulatory authorities under the new framework. The law's territorial scope is broad: it applies to Vietnamese agencies, organisations and individuals, to foreign entities operating in Vietnam, and to foreign entities processing the personal data of Vietnamese citizens regardless of where that processing occurs. The most consequential feature of the new law is its penalty framework: Article 8 introduces a tiered structure with fines of up to ten times illicitly gained revenue, a fallback fine of VND 3 billion where gains cannot be quantified, and a specific penalty of up to 5 percent of a corporate violator's prior-year annual revenue for cross-border data-transfer breaches. This is a materially strengthened enforcement posture relative to the prior decree-level regime, and it applies to both domestic and foreign-operating entities within the law's territorial scope. The shift from decree to statutory law is itself analytically significant beyond the specific penalty figures: a law passed by the National Assembly carries materially greater durability and amendment friction than a government decree, meaning Vietnam's data-protection framework is now anchored in primary legislation rather than executive rule-making, a change in the framework's legal foundation as much as in its substantive content.
Other Developments
Controller and processor duties broadened. The PDPL requires agencies and organisations to designate a data protection officer or equivalent with adequate demonstrated capacity, or to engage an external service provider, a broader trigger than the prior Decree 13 regime, which required DPO designation only for sensitive-data processing. Decree No. 356/2025/ND-CP, Article 19, further requires that data protection impact assessments be updated periodically every six months where regulated changes occur, or immediately in other cases required by law, establishing a recurring compliance cadence rather than a one-time filing obligation. The broadened DPO trigger, applying to all agencies and organisations rather than only to sensitive-data processors, materially expands the population of entities that must either build internal data-protection-officer capacity or contract for it externally, a compliance-resourcing question that a large share of small and medium domestic enterprises operating in Vietnam will now face for the first time.
Cross-border transfer permitted, but localisation persists. The PDPL permits transfers of personal data out of Vietnam under specific conditions, including consent and regulatory compliance, moving away from an outright restriction. Notwithstanding that permissive framework, Decree No. 53/2022/ND-CP continues to impose data-localisation requirements on certain service providers, meaning the cross-border-transfer permission and the localisation requirement now operate alongside one another rather than the latter having been superseded by the former; how the two interact for service categories not squarely covered by either instrument was not resolved this cycle. For foreign-operating entities structuring compliance programmes for Vietnam, the practical implication is that data-localisation obligations under Decree 53 cannot be assumed to have been superseded simply because the PDPL permits cross-border transfer in principle; both instruments must be checked against the specific service category and data type in question.
Data trading prohibited outright. The PDPL prohibits illegal data processing and the buying or selling of personal data unless expressly permitted by law. This prohibition is set against a stated enforcement rationale: Vietnamese authorities reportedly uncovered 56 illegal data-trading operations involving over 110 million records in the first half of 2025, cited as part of the justification for the law's enactment. The 110-million-record scale of the uncovered illegal trading operations is itself a signal of the personal-data exposure that motivated the legislature's move to a statutory, rather than decree-level, framework, and it suggests the enforcement rationale for the PDPL rests at least partly on volume-of-harm evidence rather than purely on doctrinal or comparative-law considerations.
Cross-Monitor Connections
No direct cross-monitor overlap was evidenced in this cycle's findings for Vietnam's data-protection developments specifically. The scale of the illegal data-trading enforcement finding, 56 operations and over 110 million records, is the kind of large-volume personal-data exposure that could in principle bear on financial-crime and identity-fraud typologies tracked elsewhere, but no specific claim connecting this cycle's Vietnam data-protection findings to a financial-integrity, world-payments, advennt, artificial-intelligence or crypto finding was located this cycle, and this brief does not assert one.
Outlook
The PDPL's tiered penalty framework and the six-month DPIA update cadence under Decree 356 Article 19 are both now live compliance obligations as of 1 January 2026, and enforcement activity under the new statutory framework, as distinct from enforcement under the superseded Decree 13, is the clearest forward signal to watch. Whether the Ministry of Public Security issues sector-specific DPIA templates beyond the general six-month cadence, and how the cross-border-transfer permission and the Decree 53 localisation requirement are reconciled for service categories not squarely addressed by either instrument, remain open questions this cycle's research pass did not resolve. Beyond the specific compliance deadlines already in force, the broader trajectory to watch is whether Vietnam's elevation of data protection to statutory law is followed by a comparable increase in visible enforcement activity, given that the stated rationale for the law rested significantly on a documented pattern of large-scale illegal data trading; a gap between the strengthened statutory penalty framework and observable enforcement outcomes would itself become a material finding in a future cycle.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Vietnam elevated data protection from decree-level regulation to statutory law this cycle, with Law No. 91/2025/QH15 (the PDPL) effective 1 January 2026 and Decree No. 356/2025/ND-CP replacing the prior Decree No. 13/2023/ND-CP as implementing instrument. The Ministry of Public Security and the Ministry of Information and Communication are the primary regulators. The PDPL broadens the DPO-designation trigger beyond sensitive-data processing, requires six-monthly DPIA updates under Decree 356 Article 19, permits cross-border data transfer under specified conditions while Decree No. 53/2022/ND-CP's localisation requirements persist alongside that permission, prohibits the buying or selling of personal data outright, and introduces a materially strengthened tiered penalty framework of up to ten times illicit gains, a VND 3 billion fallback fine, or up to 5 percent of prior-year revenue for cross-border transfer breaches specifically.
Outlook
Enforcement activity under the new statutory framework, reconciliation of the cross-border-transfer permission with Decree 53's persisting localisation requirement, and any sector-specific DPIA guidance from the Ministry of Public Security are the clearest developments to watch in coming cycles.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Comprehensive omnibus statute now in force, but institutional placement inside a security ministry (not an independent DPA) and reliance on secondary (T2) sourcing for implementing-decree specifics warrant an amber rating pending primary-text verification.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberComprehensive omnibus statute now in force, but institutional placement inside a security ministry (not an independent DPA) and reliance on secondary (T2) sourcing for implementing-decree specifics warrant an amber rating pending primary-text verification.
Sub-modules (5)
Regulator And AuthorityAmber
No independent DPA exists; enforcement is divided between MPS (A05) and MIC, with MPS's cybersecurity department as day-to-day enforcer. The MPS official portal (bocongan.gov.vn) is confirmed live per the injected seed anchor.
Claims (2):
Vietnam does not have an independent data protection authority; enforcement power is divided between the Ministry of Public Security and the Ministry of Information and Communications, with day-to-day cyber enforcement handled by the Department of Cybersecurity and High-tech Crime Prevention (A05) within MPS.
The Ministry of Public Security maintains its official enforcement/cybersecurity portal at bocongan.gov.vn, which functions as the primary regulator gateway for personal-data-protection enforcement matters in Vietnam.
Act And InstrumentsGreen
PDPL (Law 91/2025/QH15) is the primary statute, in force since 1 Jan 2026, implemented by Decree 356/2025/ND-CP; both replace Decree 13/2023/ND-CP.
Claims (2):
The Personal Data Protection Law (Law No. 91/2025/QH15), passed by the National Assembly on 26 June 2025, entered into force on 1 January 2026 and replaced Decree No. 13/2023/ND-CP as Vietnam's primary data-protection instrument.
Decree No. 356/2025/ND-CP, issued 31 December 2025 and effective 1 January 2026, implements the PDPL and formally replaces Decree 13/2023/ND-CP as the main implementing instrument.
Material ScopeGreen
PDPL classifies data into basic and sensitive personal data, with sensitive data defined broadly (location, login credentials, behavioural monitoring).
Claims (1):
The PDPL classifies personal data into 'basic personal data' and 'sensitive personal data', with sensitive data defined broadly to include location data, account log-in details and behavioural/online monitoring data.
Territorial ScopeGreen
Extraterritorial application confirmed: foreign entities processing Vietnamese citizens'/residents' data are covered.
Claims (1):
The PDPL applies extraterritorially to foreign agencies, organisations and individuals that process the personal data of Vietnamese citizens or of individuals residing in Vietnam, in addition to domestic entities.
Regulator Registration And FilingAmber
Cross-border transfer risk-assessment filings with the competent domestic authority are required; general registration regime for domestic processing not independently confirmed beyond transfer-filing context.
Claims (1):
Cross-border transfer of personal data under the PDPL/Decree 356 regime requires prescriptive risk/impact-assessment filings with the competent domestic authority in addition to contractual safeguards.
Key findings (1)
PDPL (Law 91/2025/QH15) and Decree 356/2025/ND-CP superseded Decree 13/2023/ND-CP effective 1 January 2026; enforcement remains split MPS(A05)/MIC absent an independent DPA. — source on file
Category narrative141 words
Vietnam's data-protection regime was fundamentally superseded during the seed-anchor window: the injected seed anchored on Decree 13/2023/ND-CP (PDPD), but research confirms Vietnam's National Assembly passed a standalone Personal Data Protection Law (PDPL, Law No. 91/2025/QH15) on 26 June 2025, which entered into force 1 January 2026 and replaced Decree 13 as the primary statute. Implementing Decree No. 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) operationalises the PDPL and formally supersedes Decree 13. There remains no independent EU-model DPA; enforcement is split between the Ministry of Public Security (MPS) -- principally its Department of Cybersecurity and High-tech Crime Prevention (A05) -- and the Ministry of Information and Communications (MIC), with the Ministry of National Defense playing a role in some contexts. This confirms the seed's disambiguation note: the enforcement body is security-oriented and ministry-embedded rather than an independent supervisory authority.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (7)
UncertainIAPP — Vietnam does not have an independent data protection authority; enforcement power is divided between the Ministry of Public Security and the Ministry of Information and Communications, with day-to-day cyber enforcement handled by the Department of Cybersecurity and High-tech Crime Prevention (A05) within MPS.observed
UncertainGovernment of Vietnam — The Ministry of Public Security maintains its official enforcement/cybersecurity portal at bocongan.gov.vn, which functions as the primary regulator gateway for personal-data-protection enforcement matters in Vietnam.observed
UncertainOneTrust DataGuidance — The Personal Data Protection Law (Law No. 91/2025/QH15), passed by the National Assembly on 26 June 2025, entered into force on 1 January 2026 and replaced Decree No. 13/2023/ND-CP as Vietnam's primary data-protection instrument.observed
UncertainOneTrust DataGuidance — Decree No. 356/2025/ND-CP, issued 31 December 2025 and effective 1 January 2026, implements the PDPL and formally replaces Decree 13/2023/ND-CP as the main implementing instrument.observed
UncertainIAPP — The PDPL classifies personal data into 'basic personal data' and 'sensitive personal data', with sensitive data defined broadly to include location data, account log-in details and behavioural/online monitoring data.observed
UncertainOneTrust DataGuidance — The PDPL applies extraterritorially to foreign agencies, organisations and individuals that process the personal data of Vietnamese citizens or of individuals residing in Vietnam, in addition to domestic entities.observed
UncertainIAPP — Cross-border transfer of personal data under the PDPL/Decree 356 regime requires prescriptive risk/impact-assessment filings with the competent domestic authority in addition to contractual safeguards.observed
Consent and special-category treatment are well evidenced; lawful-basis enumeration and anonymisation/pseudonymisation safe-harbour detail are thin and carry Uncertain confidence.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberConsent and special-category treatment are well evidenced; lawful-basis enumeration and anonymisation/pseudonymisation safe-harbour detail are thin and carry Uncertain confidence.
Sub-modules (4)
Lawful BasesRed
Only the predecessor Decree 13 no-consent exceptions (e.g., emergencies) were located; whether the PDPL/Decree 356 regime retains an identical or expanded lawful-basis list has not been confirmed from primary text. absent_field_provenance: searched 'Vietnam PDPL lawful bases processing without consent'.
Claims (1):
Under the predecessor Decree 13/2023/ND-CP framework, processing without consent was permitted in defined circumstances such as emergencies; whether the PDPL/Decree 356 regime retains an identical exception list has not been independently verified from primary text.
Consent ThresholdsGreen
PDPL tightens consent requirements relative to the 2023 Decree, per IAPP analysis.
Claims (1):
The PDPL tightens consent requirements relative to the 2023 Decree, requiring more specific and informed consent standards for personal-data processing.
Special CategoriesGreen
Sensitive personal data receives materially stronger protection obligations than basic personal data.
Claims (1):
Sensitive personal data (including location, account log-in and behavioural-monitoring data) receives materially stronger protection obligations than basic personal data under the PDPL/Decree 356 framework.
Pseudonymisation And AnonymisationAmber
The PDPL's definition of personal data excludes de-identified data, implying an anonymisation carve-out, but no detailed pseudonymisation safe-harbour criteria were located.
Claims (1):
The PDPL defines 'personal data' to exclude de-identified data, establishing an implicit anonymisation carve-out from the law's scope.
Category narrative52 words
The PDPL tightens consent standards relative to Decree 13 and imposes materially heavier obligations for sensitive personal data. A full GDPR Art.6-style enumeration of lawful bases distinct from consent, and a detailed pseudonymisation safe-harbour, were not independently verifiable from the secondary sources reviewed (primary Vietnamese-language text not directly retrievable in this run).
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
UncertainOneTrust DataGuidance — Under the predecessor Decree 13/2023/ND-CP framework, processing without consent was permitted in defined circumstances such as emergencies; whether the PDPL/Decree 356 regime retains an identical exception list has not been independently verified from primary text.observed
UncertainIAPP — The PDPL tightens consent requirements relative to the 2023 Decree, requiring more specific and informed consent standards for personal-data processing.observed
UncertainIAPP — Sensitive personal data (including location, account log-in and behavioural-monitoring data) receives materially stronger protection obligations than basic personal data under the PDPL/Decree 356 framework.observed
UncertainOneTrust DataGuidance — The PDPL defines 'personal data' to exclude de-identified data, establishing an implicit anonymisation carve-out from the law's scope.observed
Traffic-light rationale — AmberCore access/rectification/erasure rights are well evidenced; portability, restriction/objection, and response-deadline specifics are thin.
Sub-modules (5)
Access RightGreen
PDPL establishes rights to be informed and to access personal data.
Claims (1):
The PDPL establishes a diversified set of data-subject rights including the right to be informed and the right of access to one's personal data.
Rectification And ErasureGreen
PDPL grants correction and deletion rights, with Decree 356 detailing request procedures.
Claims (1):
The PDPL grants data subjects the right to correct and the right to delete (erase) their personal data, with Decree 356 prescribing detailed procedures for responding to such requests, including data protection impact assessments.
Restriction And ObjectionRed
No standalone restriction-of-processing or objection/profiling opt-out right was independently confirmed in the secondary sources reviewed. absent_field_provenance: searched 'Vietnam PDPL right to restrict processing object profiling'.
Data PortabilityAmber
Decree 13 (predecessor) recognised portability; retention under the PDPL/Decree 356 text is unconfirmed.
Claims (1):
The predecessor Decree 13/2023/ND-CP recognised a data-portability right for data subjects; no independent verification was found confirming portability is retained expressly under the PDPL/Decree 356 text.
Deadlines And Response WindowsRed
No specific statutory subject-access-request response deadline (distinct from the 72-hour breach-notification window) was located. absent_field_provenance: searched 'Vietnam PDPL data subject request response deadline days'.
Category narrative47 words
The PDPL establishes a diversified set of data-subject rights (to be informed, access, correction, deletion), with Decree 356 prescribing detailed request-handling procedures. Restriction/objection rights and an explicit statutory response-deadline window were not independently confirmed; portability's retention under the new regime (versus the predecessor Decree 13) is Uncertain.
Sources and claims (3)
UncertainIAPP — The PDPL establishes a diversified set of data-subject rights including the right to be informed and the right of access to one's personal data.observed
UncertainIAPP — The PDPL grants data subjects the right to correct and the right to delete (erase) their personal data, with Decree 356 prescribing detailed procedures for responding to such requests, including data protection impact assessments.observed
UncertainOneTrust DataGuidance — The predecessor Decree 13/2023/ND-CP recognised a data-portability right for data subjects; no independent verification was found confirming portability is retained expressly under the PDPL/Decree 356 text.observed
DPIA, security and breach-notification obligations are reasonably evidenced (Probable/Confirmed); DPO thresholds, joint-controller rules and retention limits are unconfirmed gaps.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberDPIA, security and breach-notification obligations are reasonably evidenced (Probable/Confirmed); DPO thresholds, joint-controller rules and retention limits are unconfirmed gaps.
Sub-modules (7)
Accountability And DpiaGreen
Decree 356 prescribes DPIA procedures; small business/start-up/micro-enterprise exemption option for five years.
Claims (1):
Decree 356/2025/ND-CP prescribes detailed procedures for data protection impact assessments (DPIAs), and small businesses, start-ups, business households and micro-enterprises may elect whether to implement DPIA-preparation obligations for a five-year grace period.
Dpo RequirementsRed
No specific DPO appointment threshold or independence requirement was located. absent_field_provenance: searched 'Vietnam PDPL DPO appointment threshold data protection officer'.
Ropa RequirementsAmber
Decree 356 introduces enhanced reporting forms and audit roles consistent with a records-of-processing style obligation, though not confirmed as a discrete ROPA mandate.
Claims (1):
Decree 356 introduces enhanced administrative and enforcement tooling, including new reporting forms, audit roles and clarified controller/processor responsibilities, consistent with a records-of-processing style obligation.
Joint Controller ArrangementsRed
No joint-controller-specific allocation-of-liability rules were located. absent_field_provenance: searched 'Vietnam PDPL joint controller liability'.
Security MeasuresAmber
General technical/organisational security obligations apply under the PDPL/Decree 356 regime, reinforced by sector-specific circulars (e.g., SBV biometric/anti-tampering rules).
Claims (1):
Under the PDPL/Decree 356 regime, controllers and processors must implement appropriate technical and organisational security measures to protect personal data, with sectoral regulators elaborating specific technical baselines.
Breach NotificationGreen
Decree 356 requires notification of breach incidents to the competent authority within 72 hours of detection.
Claims (1):
Decree 356/2025/ND-CP requires controllers to notify the competent authority of personal-data breach incidents within 72 hours of detection.
Retention And DisposalRed
No explicit statutory retention-period ceiling or disposal-duty detail was located. absent_field_provenance: searched 'Vietnam PDPL data retention period disposal'.
Category narrative42 words
Decree 356 prescribes DPIA procedures with a five-year opt-in grace period for small businesses/start-ups/micro-enterprises, enhanced reporting/audit tooling consistent with a ROPA-style obligation, general security-of-processing duties, and a 72-hour breach-notification-to-authority window. DPO appointment thresholds, joint-controller-specific rules, and retention/disposal ceilings were not independently confirmed.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
UncertainOneTrust DataGuidance — Decree 356/2025/ND-CP prescribes detailed procedures for data protection impact assessments (DPIAs), and small businesses, start-ups, business households and micro-enterprises may elect whether to implement DPIA-preparation obligations for a five-year grace period.observed
UncertainIAPP — Decree 356 introduces enhanced administrative and enforcement tooling, including new reporting forms, audit roles and clarified controller/processor responsibilities, consistent with a records-of-processing style obligation.observed
UncertainIAPP — Under the PDPL/Decree 356 regime, controllers and processors must implement appropriate technical and organisational security measures to protect personal data, with sectoral regulators elaborating specific technical baselines.observed
UncertainIAPP — Decree 356/2025/ND-CP requires controllers to notify the competent authority of personal-data breach incidents within 72 hours of detection.observed
Transfer-mechanism and localisation obligations are well evidenced (Confirmed/Probable); adequacy received/granted are confirmed absent, which is itself a legitimate red-flagged finding.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15), Decree No. 356/2025/ND-CP, and Decree No. 53/2022/ND-CP (Cybersecurity Law implementing decree)
Traffic-light rationale — AmberTransfer-mechanism and localisation obligations are well evidenced (Confirmed/Probable); adequacy received/granted are confirmed absent, which is itself a legitimate red-flagged finding.
Sub-modules (6)
Transfer MechanismsGreen
Transfers permitted under PDPL Art.19(1) enumerated conditions.
Claims (1):
Cross-border transfers of personal data under the PDPL are permitted only under specified conditions, including data-subject consent, intra-organisational transfers, transfers to processors, and transfers requested by competent state agencies (PDPL Art.19(1)).
Adequacy ReceivedRed
No evidence Vietnam has received an adequacy decision from any other regime (e.g., EU). absent_field_provenance: searched 'Vietnam adequacy decision EU GDPR received'.
Adequacy GrantedRed
No evidence Vietnam has issued formal adequacy-style determinations toward other jurisdictions; the regime instead relies on case-by-case contractual/consent mechanisms. absent_field_provenance: searched 'Vietnam PDPL adequacy list granted countries'.
Sccs And BcrsAmber
The transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism; no BCR-equivalent instrument confirmed.
Claims (1):
The PDPL/Decree 356 cross-border transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism.
Transfer Impact AssessmentAmber
A risk/impact assessment must be filed with the competent domestic authority prior to cross-border transfer.
Claims (1):
Cross-border personal-data transfers require a risk/impact assessment to be filed with the competent domestic authority prior to transfer.
Data LocalisationAmber
Decree 53/2022/ND-CP maintains data-localisation duties for certain service providers, and MPS/A05 guidance (per seed) provides the operative interpretation.
Claims (2):
Decree 53/2022/ND-CP, issued under the 2018 Cybersecurity Law, continues to impose data-localisation requirements on certain service providers notwithstanding the PDPL's separate cross-border transfer regime.
MPS/A05 operative guidance interprets the personal-data-protection framework as retaining data-localisation obligations for specified categories of service providers.
Category narrative75 words
Cross-border transfers are permitted only under enumerated conditions (consent, intra-organisational transfer, transfer to a processor, transfer requested by a competent state agency -- PDPL Art.19(1)), backed by binding contractual protections and a mandatory transfer risk/impact assessment filed with the domestic authority. Separately, Decree 53/2022/ND-CP (under the 2018 Cybersecurity Law) continues to impose data-localisation duties on certain service providers, confirming the seed's CAUTION flag. No evidence of Vietnam receiving or granting formal adequacy-style decisions was found.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
UncertainOneTrust DataGuidance — Cross-border transfers of personal data under the PDPL are permitted only under specified conditions, including data-subject consent, intra-organisational transfers, transfers to processors, and transfers requested by competent state agencies (PDPL Art.19(1)).observed
UncertainIAPP — The PDPL/Decree 356 cross-border transfer regime relies on binding contractual protections analogous to SCCs rather than a formal adequacy-list mechanism.observed
UncertainIAPP — Cross-border personal-data transfers require a risk/impact assessment to be filed with the competent domestic authority prior to transfer.observed
UncertainOneTrust DataGuidance — Decree 53/2022/ND-CP, issued under the 2018 Cybersecurity Law, continues to impose data-localisation requirements on certain service providers notwithstanding the PDPL's separate cross-border transfer regime.observed
UncertainGovernment of Vietnam — MPS/A05 operative guidance interprets the personal-data-protection framework as retaining data-localisation obligations for specified categories of service providers.observed
Financial, telecom and education overlays are reasonably evidenced; health/employment/credit/insurance sub-modules carry explicit evidentiary gaps.
Primary frameworkSector-specific circulars/decrees layered on the PDPL/Decree 356 baseline (SBV Circular 77/2025/TT-NHNN; MOET Circular 49/2026/TT-BGDDT)
Traffic-light rationale — AmberFinancial, telecom and education overlays are reasonably evidenced; health/employment/credit/insurance sub-modules carry explicit evidentiary gaps.
Sub-modules (7)
Financial Sector OverlayGreen
SBV Circular 77/2025/TT-NHNN imposes mobile-banking security and biometric standards on credit institutions.
Claims (1):
The State Bank of Vietnam (SBV) issued Circular 77/2025/TT-NHNN amending online-banking safety rules, requiring credit institutions to deploy anti-tampering safeguards in mobile banking apps from 1 March 2026 and biometric-matching standards (including Presentation Attack Detection meeting ISO 30107 Level 2) from 1 July 2026.
Health Sector OverlayRed
No health-sector-specific data-protection overlay was located. absent_field_provenance: searched 'Vietnam health data protection law HIPAA equivalent 2026'.
Telecoms And EprivacyAmber
Biometric re-authentication and SIM self-authentication rules layer identity-verification duties onto telecom data processing; no dedicated ePrivacy/cookie-consent instrument confirmed.
Claims (1):
Vietnam introduced mandatory facial-recognition re-authentication for mobile subscribers changing devices and self-authentication of SIM ownership via the VNeID app, effective 15 April 2026, layering biometric identity-verification duties onto telecom data processing.
Employment DataRed
No employment-specific data-protection code was located. absent_field_provenance: searched 'Vietnam employment data protection code PDPL'.
Credit And ScoringRed
No credit-scoring-specific data rules were located. absent_field_provenance: searched 'Vietnam credit scoring data protection rules'.
EducationAmber
MOET Circular 49/2026/TT-BGDDT regulates technology use in education with data-protection emphasis.
Claims (1):
Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT regulating technology use in education, emphasising data protection, interoperability and ethical AI use.
InsuranceRed
No insurance-sector-specific data-protection overlay was located. absent_field_provenance: searched 'Vietnam insurance sector data protection rules PDPL'.
Category narrative64 words
Confirmed sectoral overlays: (i) financial sector -- SBV Circular 77/2025/TT-NHNN imposing mobile-banking anti-tampering and biometric-matching (PAD/ISO 30107 Level 2) standards on credit institutions with staged 2026 effective dates; (ii) telecoms -- mandatory facial-recognition re-authentication and VNeID SIM self-authentication; (iii) education -- MOET Circular No. 49/2026/TT-BGDDT on technology use in education emphasising data protection. Health, employment, credit-scoring and insurance sectoral overlays were not independently confirmed.
Sources and claims (3)
UncertainOneTrust DataGuidance — The State Bank of Vietnam (SBV) issued Circular 77/2025/TT-NHNN amending online-banking safety rules, requiring credit institutions to deploy anti-tampering safeguards in mobile banking apps from 1 March 2026 and biometric-matching standards (including Presentation Attack Detection meeting ISO 30107 Level 2) from 1 July 2026.observed
UncertainOneTrust DataGuidance — Vietnam introduced mandatory facial-recognition re-authentication for mobile subscribers changing devices and self-authentication of SIM ownership via the VNeID app, effective 15 April 2026, layering biometric identity-verification duties onto telecom data processing.observed
UncertainOneTrust DataGuidance — Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT regulating technology use in education, emphasising data protection, interoperability and ethical AI use.observed
Only direct-marketing restriction is evidenced; five of six sub-modules carry explicit absent_field_provenance gaps -- consistent with Vietnam having no dedicated adtech/ePrivacy instrument distinct from the general PDPL.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) -- general marketing/advertising restriction only; no dedicated adtech instrument identified
Traffic-light rationale — RedOnly direct-marketing restriction is evidenced; five of six sub-modules carry explicit absent_field_provenance gaps -- consistent with Vietnam having no dedicated adtech/ePrivacy instrument distinct from the general PDPL.
Sub-modules (6)
Cookies And TrackersRed
No dedicated cookie/tracker consent regime distinct from general PDPL consent rules was located. absent_field_provenance: searched 'Vietnam cookie consent law ePrivacy equivalent'.
Dark PatternsRed
No dark-pattern-specific prohibition was located. absent_field_provenance: searched 'Vietnam dark patterns consent law PDPL'.
Opt Out SignalsRed
No recognition of technical opt-out signals (e.g., Global Privacy Control) was located. absent_field_provenance: searched 'Vietnam Global Privacy Control opt-out signal recognition'.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room-specific rules were located. absent_field_provenance: searched 'Vietnam data clean room rules PDPL'.
Cross Context AdvertisingRed
No CPRA-style 'sale'/'share' cross-context-advertising concept was located. absent_field_provenance: searched 'Vietnam cross-context advertising data sale PDPL'.
Direct MarketingAmber
PDPL restricts processing for marketing/advertising purposes and prohibits unauthorised trading of personal information.
Claims (1):
The PDPL imposes restrictions on personal-data processing for marketing and advertising purposes, alongside its general prohibition on the purchase and sale of personal information.
Category narrative41 words
The PDPL restricts personal-data processing for marketing/advertising purposes and prohibits unauthorised buying/selling of personal information. No dedicated cookie/ePrivacy-style consent regime, dark-pattern prohibition, opt-out-signal (e.g., GPC) recognition, clean-room/DCR framework, or cross-context-advertising ('sale'/'share') concept equivalent to CPRA was located in the sources reviewed.
Sources and claims (1)
UncertainOneTrust DataGuidance — The PDPL imposes restrictions on personal-data processing for marketing and advertising purposes, alongside its general prohibition on the purchase and sale of personal information.observed
AI-law and biometric evidence is strong (Confirmed/Probable); Art.22-equivalent profiling/ADM transparency, genetic data, and surveillance carve-outs remain unconfirmed gaps.
Primary frameworkLaw on Artificial Intelligence (effective 1 March 2026) and Decree No. 142/2026/ND-CP; PDPL/Decree 356 for general data-processing baseline
Traffic-light rationale — AmberAI-law and biometric evidence is strong (Confirmed/Probable); Art.22-equivalent profiling/ADM transparency, genetic data, and surveillance carve-outs remain unconfirmed gaps.
Sub-modules (6)
Profiling RestrictionsRed
No Art.22-equivalent profiling restriction was independently confirmed. absent_field_provenance: searched 'Vietnam PDPL profiling restriction automated decision'.
Automated Decision Making TransparencyRed
No ADM transparency/explanation right distinct from general access rights was confirmed. absent_field_provenance: searched 'Vietnam PDPL automated decision making transparency explanation right'.
Ai Risk AssessmentsGreen
AI Law and Decree 142/2026/ND-CP establish risk-based classification and conformity-assessment obligations for AI systems.
Claims (2):
Vietnam's first standalone AI Law, adopted December 2025 and effective 1 March 2026, introduces a risk-based classification and conformity-assessment framework for AI systems with concepts similar to the EU AI Act, and supersedes the AI provisions of the Law on Digital Technology Industry (effective 1 January 2026).
Decree No. 142/2026/ND-CP mandates AI risk classification and conformity-assessment obligations based on defined risk levels and criteria, implementing the AI Law.
Biometric RegimeGreen
Sector regulators (SBV, telecom authorities) impose specific biometric-verification technical standards.
Claims (1):
Sector regulators have imposed specific biometric-verification standards, including SBV-mandated Presentation Attack Detection (PAD) meeting ISO 30107 Level 2 for mobile-banking biometric authentication and mandatory facial-recognition re-authentication for mobile subscribers changing devices.
Genetic DataRed
No genetic-data-specific regime was located. absent_field_provenance: searched 'Vietnam genetic data protection law PDPL'.
State Surveillance CarveoutsRed
No national-security/state-surveillance carve-out detail specific to the PDPL was located. absent_field_provenance: searched 'Vietnam PDPL national security exemption state surveillance carveout'.
Key findings (1)
Vietnam's first standalone AI Law and Decree 142/2026/ND-CP introduce an EU-AI-Act-like risk-classification/conformity-assessment regime, effective 1 March 2026. — source on file
Category narrative69 words
Vietnam's first standalone AI Law (adopted December 2025, effective 1 March 2026) introduces an EU-AI-Act-like risk-based classification and conformity-assessment framework, superseding the AI provisions of the Law on Digital Technology Industry. Decree 142/2026/ND-CP further mandates AI risk classification/conformity assessment. Biometric-verification standards are confirmed via SBV mobile-banking rules and telecom facial-recognition re-authentication. Profiling restrictions, ADM transparency rights, genetic-data rules and state-surveillance carve-outs specific to the PDPL were not independently confirmed.
Sources and claims (3)
UncertainIAPP — Vietnam's first standalone AI Law, adopted December 2025 and effective 1 March 2026, introduces a risk-based classification and conformity-assessment framework for AI systems with concepts similar to the EU AI Act, and supersedes the AI provisions of the Law on Digital Technology Industry (effective 1 January 2026).observed
UncertainOneTrust DataGuidance — Decree No. 142/2026/ND-CP mandates AI risk classification and conformity-assessment obligations based on defined risk levels and criteria, implementing the AI Law.observed
UncertainOneTrust DataGuidance — Sector regulators have imposed specific biometric-verification standards, including SBV-mandated Presentation Attack Detection (PAD) meeting ISO 30107 Level 2 for mobile-banking biometric authentication and mandatory facial-recognition re-authentication for mobile subscribers changing devices.observed
Only a tangential education-settings signal was found; four of five sub-modules carry explicit absent_field_provenance gaps, warranting escalation to primary Vietnamese-language text.
Traffic-light rationale — RedOnly a tangential education-settings signal was found; four of five sub-modules carry explicit absent_field_provenance gaps, warranting escalation to primary Vietnamese-language text.
Sub-modules (5)
Age VerificationRed
No minimum age-of-consent threshold for data processing was located. absent_field_provenance: searched 'Vietnam PDPL children minors data protection consent parental biometric facial recognition'.
Parental ConsentRed
No parental-consent mechanism analogous to GDPR Art.8 or COPPA was located. absent_field_provenance: same search as age_verification.
Minor Profiling BansRed
No minor-specific profiling ban was located. absent_field_provenance: searched 'Vietnam PDPL minor profiling ban advertising children'.
Education SettingsAmber
MOET Circular 49/2026/TT-BGDDT regulates technology use in education with a data-protection emphasis, relevant to minors' data in schools, though it is not itself a minors-specific data-protection statute.
Claims (1):
Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT to regulate technology use in education settings, with an emphasis on data protection, interoperability and ethical AI use, relevant to the processing of minors' data in schools.
Dependent AdultsRed
No provisions specific to dependent adults (elderly, mentally incapacitated) were located. absent_field_provenance: searched 'Vietnam data protection dependent adults elderly incapacitated'.
Category narrative55 words
Despite targeted searches, no PDPL/Decree 356 provisions specifying a minimum age of consent, a parental-consent mechanism, or minor-specific profiling bans were located in the secondary sources reviewed. A confirmed education-sector circular (MOET Circular 49/2026/TT-BGDDT) touches technology use in schools but does not itself establish a discrete minors' data-protection regime. Dependent-adult (elderly/incapacitated) protections were not located.
Sources and claims (1)
UncertainOneTrust DataGuidance — Vietnam's Ministry of Education and Training issued Circular No. 49/2026/TT-BGDDT to regulate technology use in education settings, with an emphasis on data protection, interoperability and ethical AI use, relevant to the processing of minors' data in schools.observed
Penalty framework is well evidenced (Confirmed); enforcement track record, funding/capacity, collective redress and private right of action are unconfirmed gaps consistent with the regime's short operating history.
Primary frameworkPersonal Data Protection Law (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP
Traffic-light rationale — AmberPenalty framework is well evidenced (Confirmed); enforcement track record, funding/capacity, collective redress and private right of action are unconfirmed gaps consistent with the regime's short operating history.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
PDPL sets tiered administrative/criminal penalties for violations.
Claims (1):
The PDPL provides for administrative and criminal penalties for violations, including fines of up to ten times the illicit gains for unlawful trading of personal data, up to 5% of the offending entity's prior-year revenue for cross-border transfer violations, and fines of up to VND 3 billion for other breaches.
Enforcement Activity IndexAmber
No significant published enforcement decisions were located; regime newly in force since 1 Jan 2026.
Claims (1):
As the PDPL/Decree 356 regime has been in force only since 1 January 2026, no significant published enforcement decisions or fines against controllers were located in the sources reviewed as of the research date.
Regulator Funding And CapacityRed
No data on MPS/A05 staffing or budget for PDPL enforcement was located. absent_field_provenance: searched 'Vietnam MPS A05 cybersecurity department budget headcount 2026'.
Collective Redress And Class ActionsRed
No dedicated collective-redress/class-action mechanism for data-protection claims was identified. absent_field_provenance: searched 'Vietnam class action data protection collective redress civil procedure'.
Private Right Of ActionRed
Not confirmed whether the PDPL provides a direct private right of action distinct from administrative/criminal enforcement. absent_field_provenance: searched 'Vietnam PDPL private right of action civil suit data subject'.
Recent Developments 180DAmber
Within 180 days preceding this research, Vietnam's AI Law took effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification was issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceeded through staged 2026 effective dates, alongside continued PDPL/Decree 356 implementation bedding-in.
Claims (1):
Within the 180 days preceding this research (August 2026), Vietnam's regulatory landscape saw the AI Law take effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceed through staged effective dates into July 2026, alongside continued PDPL/Decree 356 implementation.
Category narrative73 words
The PDPL sets tiered administrative/criminal penalties (up to 10x illicit gains for unlawful data trading; up to 5% of prior-year revenue for cross-border violations; up to VND 3 billion for other breaches). Because the regime only entered force 1 January 2026, no significant published enforcement decisions were located as of the August 2026 research date. Regulator funding/capacity data, collective-redress mechanisms, and a private right of action distinct from administrative enforcement were not confirmed.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (3)
UncertainOneTrust DataGuidance — The PDPL provides for administrative and criminal penalties for violations, including fines of up to ten times the illicit gains for unlawful trading of personal data, up to 5% of the offending entity's prior-year revenue for cross-border transfer violations, and fines of up to VND 3 billion for other breaches.observed
UncertainOneTrust DataGuidance — As the PDPL/Decree 356 regime has been in force only since 1 January 2026, no significant published enforcement decisions or fines against controllers were located in the sources reviewed as of the research date.observed
UncertainIAPP — Within the 180 days preceding this research (August 2026), Vietnam's regulatory landscape saw the AI Law take effect (1 March 2026), Decree 142/2026/ND-CP on AI risk classification issued, and SBV Circular 77/2025/TT-NHNN mobile-banking security amendments proceed through staged effective dates into July 2026, alongside continued PDPL/Decree 356 implementation.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
52.94
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Vietnam
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (34 category placement(s)), 17 source(s) in the cumulative register.
Module 1 (regulator_and_framework), module 5's transfer/localisation core, module 6's financial overlay, and module 8's AI-law core rest on at least one T1-adjacent anchor (bocongan.gov.vn per seed) plus multiple corroborating T2 sources (DataGuidance, IAPP), and are the strongest-evidenced areas. Modules 3 (data_subject_rights) and 4 (controller_processor_duties) are moderately evidenced via T2 secondary summaries but lack DPO-threshold, retention-limit, and full deadline specifics. Modules 7 (adtech_and_commercial_privacy), 9 (children_and_vulnerable_groups), and several sectoral sub-modules (health, employment, credit, insurance) rely entirely on absent_field_provenance disclosures -- no T1/T2/T3 evidence located despite targeted searches. Critically, the injected seed anchor (Decree 13/2023/ND-CP as the operative statute) was found to be superseded: the PDPL (Law 91/2025/QH15) and Decree 356/2025/ND-CP now govern, entering force 1 January 2026 -- this supersession is the single most material finding of this run and should be flagged upstream.
Unresolved questions (9):
Does the PDPL/Decree 356 regime retain, expand, or replace the Decree-13-era lawful-basis exceptions (e.g., emergency processing without consent)?
Is there a codified DPO appointment threshold and independence requirement under Decree 356?
Is data portability retained as an express right under the PDPL, or was it dropped relative to Decree 13?
What is the statutory SAR/response-window deadline (distinct from the 72-hour breach-notification window)?
Has Vietnam received or granted any formal adequacy-equivalent determination with any other jurisdiction?
What is the minimum age of consent and parental-consent mechanism (if any) under the PDPL for minors' data?
Has any enforcement action, fine, or published decision been issued under the PDPL/Decree 356 regime since 1 January 2026?
Does the PDPL provide a private right of action / direct court access for data subjects, distinct from administrative and criminal enforcement?
Does the revamped 2025/2026 Cybersecurity Law (effective 1 July 2026) alter the data-localisation scope beyond Decree 53/2022/ND-CP?