Vietnam has overhauled its personal data rules. On June 26, 2025, the National Assembly of Vietnam adopted the Personal Data Protection Law No. 91/2025/QH15. On December 31, 2025, the Vietnamese Government issued Decree No. 356/2025/ND-CP, which sets out detailed provisions and implementation measures. Both instruments took effect on January 1, 2026, and Decree 356 replaced the previous Decree No. 13/2023/ND-CP.
For Chinese-invested companies operating in Vietnam, the change goes beyond updating privacy policies or consent language. It affects employment management, customer operations, group data sharing, cloud systems, headquarters reporting, digital tools and third-party cooperation.
Vietnam moves from decree-based regulation to a statutory framework
The new law and Decree 356 now sit at the center of personal data protection in Vietnam. The rules cover the full life cycle of personal data, including collection, storage, use, sharing, transfer and deletion. Companies should treat personal data protection as a separate compliance track connected to HR, customer management, group governance and information systems.
The scope is broad. The law applies to Vietnamese domestic agencies, organizations and individuals. It also applies to foreign entities and individuals in Vietnam and to offshore parties directly involved in processing personal data of Vietnamese citizens and certain Vietnam-based persons. In practical terms, the law reaches well beyond internet platforms or technology companies.
In substance, the framework covers the full personal-data life cycle and introduces classification of personal data and sensitive personal data, controller and processor roles, data-subject rights, consent and processing rules, personal-data processing and cross-border transfer impact assessments, breach reporting, special rules for employees and other common scenarios, organizational protection duties, regulatory responsibilities and legal liability.
Changes with the greatest practical impact
Personal data processing is defined broadly
Processing includes collection, analysis, aggregation, encryption, decryption, modification, deletion, destruction, de-identification, provision, disclosure, transfer and other operations affecting data. Recruitment, onboarding, attendance systems, access control, facial recognition, payroll, customer management, after-sales service, cloud backup, headquarters access and outsourced processing may all fall within the regulated scope.
Consent requirements are stricter
Consent must be voluntary and informed. Data subjects should understand the data types, processing purposes, controller or controller-processor role and their rights and obligations. Consent should be separated by processing purpose, and silence or non-response cannot be treated as consent. Broad authorization clauses, default ticks and bundled consent mechanisms should therefore be reviewed.
Group sharing and cloud systems can trigger transfer rules
Cross-border transfer can include transferring data stored in Vietnam to an overseas storage system, sending personal data from a Vietnamese entity to an offshore organization or individual, or using an offshore platform to process personal data collected in Vietnam. Internal group transfers to headquarters, regional shared-service centers, overseas ERP, HR or CRM systems, overseas email systems or cloud platforms are not automatically outside the transfer framework.
Impact assessments and filing records become required procedures
Controllers and controller-processors must prepare and retain personal data processing impact assessment dossiers and submit them within 60 days after processing begins. Cross-border transferors must also prepare cross-border transfer impact assessment dossiers and submit them within 60 days after the first transfer. Processors must prepare and retain assessment records according to their arrangements with the controller or controller-processor, and Decree 356 further details the filing process. These materials usually need to cover processing purpose, data categories, data flows, consent, retention and deletion, security measures, system structure, onward transfers, self-assessment and risk mitigation.
Organizational responsibility must be assigned
Companies should designate qualified personal data protection personnel or departments, or engage service providers where permitted. The designation should be made in written form and clarify functions, responsibilities and authority. Designated personnel will generally need at least a college degree, two years of relevant experience in areas such as legal, information technology, cybersecurity, data security, risk management, compliance control or HR management, and training in personal data protection law and professional skills. For Chinese-invested companies, personal data protection should become a joint governance matter for legal, HR, IT, information security, internal control and business teams.
Penalties are materially higher
The law introduces significantly higher exposure. Administrative penalties for buying or selling personal data can reach up to ten times the illegal gains. Organizational violations of cross-border transfer rules can be punished by reference to up to 5% of the previous year's revenue. For other personal data violations, the maximum fine for an organization can reach VND 3 billion, while individuals are generally subject to half of the organizational level. Civil liability and criminal liability may also arise where damage or serious circumstances are involved.
High-risk scenarios for Chinese-invested companies in Vietnam
Employment is often the first area requiring review. The law contains specific requirements for recruiting, managing and using employee personal data, including collecting only information consistent with the recruitment purpose, deleting or destroying candidate data when a candidate is not hired, and deleting or destroying employee personal data when the employment relationship ends as required by law. Recruitment files, background checks, onboarding documents, access and attendance systems, dormitory management, payroll, resignation handover, facial recognition and location-based clock-in tools should be assessed against legality, necessity, notice, consent, retention and deletion requirements, and technical employee-management tools should be lawful, necessary and disclosed to employees.
Customer and marketing operations also require attention, especially for retail, e-commerce, platform, app and other consumer-facing businesses. Customer registration, targeted marketing, cookies or tracking tools, user profiling, offshore analytics, customer-service systems and monitoring in public spaces should be reviewed for notice, consent, access control, storage, deletion and cross-border flows. Behavioral or personalized advertising generally requires data-subject consent and a mechanism to reject or stop receiving advertising. Audio or video recording in public spaces may be allowed without consent in limited circumstances, but companies still need notice, a lawful purpose and deletion or destruction after the necessary period.
Group-wide management models may be the most challenging. Many Chinese groups connect Vietnamese subsidiaries to unified HR, finance, risk-control, audit, customer-service and supply-chain platforms. Under the new rules, those arrangements can simultaneously raise processing, role-identification and cross-border transfer issues.
Recommended response
First, complete a data mapping exercise covering employees, candidates, customers, suppliers, visitors, dealers and end users. The company should know where the data comes from, what is processed, why it is processed, how long it is kept, who can access it, whether it is shared and whether it crosses borders.
Second, rebuild notice and consent documents. Recruitment forms, onboarding documents, employment contracts, probation documents, employee handbooks, privacy policies, customer registration pages, marketing consents and cookie notices should be rewritten around the actual processing purposes and data flows. Consent mechanisms should avoid default ticks, broad authorization and forced bundling with unrelated contractual purposes. For employment management, companies can also add internal disciplinary rules for unauthorized sale, leakage or illegal sharing of personal data and define the boundary for employee-data processing in employment documents.
Third, treat processing impact assessments and cross-border transfer impact assessments as structured compliance projects. Some exceptions may reduce the need for a transfer assessment in specific scenarios, but they do not remove other duties such as notice, consent, minimization, security, retention, third-party control and rights response.
Fourth, designate a responsible department or officer and establish a cross-functional workflow. Even if the company does not build a large standalone team, it should document the lead department, responsibility boundaries, approval authority and escalation mechanism, and ensure coordination among legal, HR, IT, information security, business and internal-control teams. It should also create a unified intake, verification, response and recordkeeping process for data-subject requests such as access, correction, deletion and withdrawal of consent. If the company provides data-processing services to external customers, such as entrusted processing, profiling or data analysis, it should also assess whether Vietnam's special rules for personal data processing services are triggered.
Fifth, improve technical and internal-control measures. Companies should classify personal data, apply strict least-privilege access, maintain approval and audit trails for bulk exports, USB copying, overseas access, cloud backup and third-party interfaces, and adopt special rules for biometric data, location data and monitoring footage. The law requires controllers, controller-processors and third parties to notify the dedicated personal data protection authority within 72 hours when a personal data protection violation may harm national defense or security, social order, or a data subject's life, health, reputation or property. Processors must promptly notify the controller or controller-processor and support the relevant filing and response work. Internal incident response therefore needs fast identification, fact preservation, assessment and remediation.
Sixth, pay attention to transitional arrangements without over-reading the exemptions. Consents, processing impact assessment dossiers and cross-border transfer impact assessment dossiers already obtained or accepted under the previous decree may continue to be used, but changes should be updated under the new law. Some small enterprises, start-ups, household businesses and micro enterprises may benefit from limited exemptions for certain assessment, update or personnel-appointment requirements; however, enterprises providing personal-data processing services, directly processing sensitive personal data or handling data of a large number of data subjects generally cannot rely on those exemptions. A small headcount does not by itself remove the basic duties: if the company processes employee, candidate, customer, supplier or visitor data in Vietnam, the basic personal data protection obligations still need to be handled.
Conclusion
Vietnam's shift from decree-based regulation to a statute raises the compliance bar for companies operating in Vietnam. For Chinese-invested companies, the change is not a one-time document update. It affects employment, customer operations, group collaboration, information systems and external cooperation.
Companies should move early from informal administration to documented governance. Those that map data, identify roles, update notices, complete assessments and control transfers will be better placed to keep Vietnam operations connected to group systems without leaving major compliance gaps.