⚠️ COMPLIANCE GUIDE

Vietnam Data Protection
Compliance Guide 2026

Everything you need to know about PDPD (Decree 13/2023) and the Cybersecurity Law

⚠️ KEY TAKEAWAY

Vietnam's Personal Data Protection Decree (PDPD) has been in effect since July 1, 2023. Businesses must obtain explicit consent, implement security measures, and may face penalties up to 5% of annual revenue for serious violations.

This law applies to ALL businesses processing data of Vietnamese citizens, regardless of where the business is located.

1. Overview of Vietnam's Data Protection Laws

Vietnam's data protection framework consists of two main pieces of legislation:

Personal Data Protection Decree (PDPD) - Decree 13/2023/NĐ-CP

Effective July 1, 2023, this is Vietnam's first comprehensive personal data protection law. It establishes:

Cybersecurity Law - Law 24/2018/QH14

Effective January 1, 2019, this law focuses on:

⚠️ Who Must Comply?

ANY business that collects, stores, or processes personal data of Vietnamese citizens—including foreign companies selling to Vietnamese customers, employing Vietnamese workers, or partnering with Vietnamese businesses.

2. Key Compliance Requirements

Consent Requirements

You must obtain explicit, informed consent before collecting personal data:

Data Subject Rights

Vietnamese citizens have the right to:

Sensitive Personal Data

Extra protections apply to "sensitive" categories:

✅ Impact Assessment Required

Processing sensitive data requires a Data Protection Impact Assessment (DPIA) and may require registration with the Ministry of Public Security.

3. Penalties for Non-Compliance

Violation Type Penalty (VND) Penalty (USD)
Minor violations (incomplete privacy policy, poor documentation) 20-40 million ~$800-1,600
Moderate violations (collecting data without proper consent) 40-60 million ~$1,600-2,400
Serious violations (selling personal data, major breaches) 60-100 million ~$2,400-4,000
Very serious violations (gross negligence, repeated offenses) Up to 5% of annual revenue Varies
Criminal violations (intentional harm, data theft) Up to 7 years imprisonment

4. Data Localization Requirements

Under the Cybersecurity Law, certain businesses must store data locally in Vietnam:

Who Must Localize?

What Data Must Be Localized?

⚠️ Cross-Border Data Transfers

Transferring personal data outside Vietnam requires a documented Impact Assessment and appropriate safeguards. Transfers to countries without adequate protection may require additional measures or government approval.

5. Compliance Checklist

📋 Essential Compliance Steps

Data Mapping — Identify all personal data you collect, where it's stored, how it flows, and who has access
Privacy Policy — Create/update your privacy policy in Vietnamese and English with all required disclosures
Consent Mechanisms — Implement clear, specific, granular consent collection for all data processing activities
Data Subject Rights Portal — Create mechanism for users to access, correct, delete, and export their data
Security Measures — Implement encryption, access controls, monitoring, and other technical safeguards
Data Processing Agreements — Sign DPAs with all vendors, partners, and third parties who process data
Impact Assessment — Complete DPIA for sensitive data processing or cross-border transfers
Breach Response Plan — Establish incident response and notification procedures (72-hour notification)
Local Storage — If required, implement local data storage infrastructure in Vietnam
Staff Training — Train all employees on data protection requirements and procedures

6. Frequently Asked Questions

Does PDPD apply to foreign companies?

Yes. If you process personal data of Vietnamese citizens, PDPD applies regardless of where your business is headquartered. This includes foreign e-commerce sites, SaaS companies, and any business with Vietnamese customers or employees.

How is PDPD different from GDPR?

While similar in many ways, key differences include: stricter data localization requirements, different penalty structures, registration requirements for sensitive data, and specific provisions for government data access. GDPR compliance is a good foundation but doesn't guarantee PDPD compliance.

Can I use AWS/Azure/GCP for Vietnamese data?

Yes, but with caveats. Singapore-based regions are commonly used for Vietnam-serving workloads. For certain data categories (government, critical infrastructure), local Vietnam storage may be required. Implement encryption and access controls for cross-border transfers.

Do I need a Data Protection Officer (DPO)?

PDPD doesn't explicitly require a DPO like GDPR does. However, businesses processing large volumes of personal data or sensitive data should designate someone responsible for data protection compliance.

What's the timeline for compliance?

The law is already in effect (since July 2023). Businesses should be compliant now. If you're not yet compliant, prioritize: privacy policy updates, consent mechanisms, and security measures as immediate actions.

Need Help with Compliance?

Our team can help you assess your current compliance status, implement required controls, and build cloud infrastructure that meets Vietnam's data protection requirements.

🛡️ Get Compliance Assessment

Or read our Data Privacy Story →