Vietnam Personal Data Protection Law (Law No. 91/2025/QH15)

Vietnam's first data protection statute, replacing Decree 13/2023: lawful bases, data subject rights, 72-hour breach notification, cross-border transfer impact assessments, and administrative fines up to 5 percent of revenue for unlawful transfers.

JurisdictionVietnam
CategoryPrivacy & Data Protection
StatusActive
Effective date
Latest development

Analysis

Vietnam’s Law on Personal Data Protection (PDPL) – Law No. 91/2025/QH15 is Vietnam’s first comprehensive personal data statute, adopted by the National Assembly on 26 June 2025 and effective 1 January 2026, replacing Decree 13/2023/ND-CP as the primary framework for personal data protection in Vietnam. According to official publications and legal updates, it introduces structured lawful bases, enhanced data subject rights, breach notification, cross‑border transfer controls, and significant administrative fines (including up to 5% of revenue for certain unlawful cross‑border transfers).Law 91/2025/QH15 – English version, Vietnam Law Library Official Gazette entry for Law 91/2025/QH15 – Government Portal Law on Personal Data Protection No. 91/2025/QH15 – summary Vietnam’s New Personal Data Protection Law – business overview Vietnam PDPL overview – Uniconsent Guidance article on Law 91/2025/QH15 structure and effective date


Key Requirements

Below are the main substantive and organisational requirements reflected in Law No. 91/2025/QH15 and related official and expert summaries. Each point is supported by direct links.

  • Lawful bases for processing personal data
  • The PDPL introduces structured lawful bases for processing, similar in concept to other modern data protection laws, including consent and other legal grounds defined in the statute and related guidance.Vietnam PDPL overview – Uniconsent
  • Decree 13/2023/ND-CP already set out lawful bases and requirements for consent and processing, and the PDPL replaces Decree 13 as the primary framework, carrying forward and systematizing lawful processing grounds.Decree 13/2023/ND-CP – English text
  • Commentaries highlight that processing must be grounded in a clear legal basis and that controllers must be able to demonstrate compliance with these PDPL bases.Data protection laws in Vietnam – DLA Piper overview
  • Data subject rights
  • The PDPL codifies data subject rights such as access, correction, deletion, restriction, and objection, consistent with earlier Decree 13 rights and extended in the law.Law 91/2025/QH15 – English version
  • Decree 13 previously provided detailed rights for data subjects, including right to be informed, right to access, right to withdraw consent, and right to delete data, which are referenced as a baseline that the PDPL now supersedes.Decree 13/2023/ND-CP – English text
  • Legal commentaries emphasize that organizations must establish mechanisms to respond to data subject requests within legal timeframes, reinforcing PDPL obligations.Data protection laws in Vietnam – DLA Piper overview
  • Data breach notification (including 72‑hour window)
  • The PDPL introduces a breach notification obligation requiring organizations to notify authorities within a specified period; commentary and practice guidance align this with a 72‑hour notification window following discovery of a qualifying personal data breach.Vietnam PDPL overview – Uniconsent
  • Earlier Decree 13 and cybersecurity regulations (including under the Ministry of Public Security) already required timely reporting of incidents, which practice guides note has now been refined and integrated in the PDPL regime.Decree 13/2023/ND-CP – English text
  • Law firm analyses describe strict timelines for reporting personal data breaches to the Ministry of Public Security (MPS)/A05, referencing the PDPL’s reporting obligations and administrative risk.Data protection laws in Vietnam – DLA Piper overview
  • Cross‑border data transfer requirements (including impact assessments)
  • The PDPL imposes requirements for cross‑border transfers of personal data, including transfer impact assessments, documentation, and conditions for approval or registration.Vietnam’s New Personal Data Protection Law – Tilleke
  • Expert articles highlight mandatory cross‑border transfer impact assessments for certain categories of transfers, especially those involving sensitive data or large‑scale processing.Vietnam PDPL overview – Uniconsent
  • Decree 13 previously required assessment and registration of cross‑border transfers with the MPS, and PDPL consolidates and strengthens these rules.Decree 13/2023/ND-CP – English text
  • Organizational measures: DPO / Data Protection Department
  • The PDPL requires organizations processing personal data to appoint a Data Protection Officer (DPO) or establish an internal Data Protection Department (DPD) to oversee compliance.Data protection laws in Vietnam – DLA Piper overview
  • Decree 13 specified that controllers, processors and controlling‑processing entities must assign a unit specializing in personal data protection and appoint a DPO, and inform the Ministry of Public Security (A05).EY Vietnam legal update on Decree 13
  • PDPL commentary confirms that all data controllers and processors must appoint a DPO, reinforcing continuity from Decree 13 but now grounded at law level.Vietnam PDPL overview – Uniconsent

Compliance Challenges

Organizations commonly face challenges implementing PDPL requirements, especially given the transition from Decree 13 and the strong enforcement posture.

  • Complex and evolving regulatory landscape
  • Businesses must navigate multiple overlapping instruments: PDPL (Law 91/2025/QH15), Decree 13/2023/ND-CP, cybersecurity laws, and sectoral regulations, which can create uncertainty about which requirements apply and when Decree 13 provisions are superseded.Decree 13/2023/ND-CP – English text
  • Legal updates describe the PDPL as replacing Decree 13 as the main framework from 1 January 2026, requiring organizations to re‑map compliance programs.Vietnam PDPL overview – Uniconsent
  • Commentaries emphasize that companies must re‑evaluate cross‑border transfers and consent models as PDPL introduces new conditions and impact assessment obligations.Vietnam’s New Personal Data Protection Law – Tilleke
  • Data mapping and inventory difficulties
  • Rouse’s business guidance identifies data mapping (identifying all personal data types, classifying general vs sensitive, tracing flows) as a key compliance step, and notes that many organizations lack accurate inventories.Vietnam PDPL – compliance steps (Rouse)
  • Companies with legacy systems may find it difficult to consolidate data records and trace cross‑border flows necessary for PDPL impact assessments.Data protection laws in Vietnam – DLA Piper overview
  • Implementation guides highlight that organizations must identify controllers, processors, and controlling‑processing entities, which can be challenging in multi‑entity group structures.EY Vietnam legal update on Decree 13
  • Appointment and resourcing of DPO/DPD
  • Decree 13 and PDPL require a specialized unit and DPO, which may be burdensome for small and medium enterprises or foreign companies with limited local presence.Decree 13/2023/ND-CP – English text
  • EY’s update notes challenges in designating qualified DPOs and informing MPS (A05), especially where internal expertise is lacking.EY Vietnam legal update on Decree 13
  • Uniconsent’s PDPL summary stresses that all controllers and processors must appoint a DPO, which increases compliance costs and organizational complexity.Vietnam PDPL overview – Uniconsent
  • Breach notification and incident response
  • The 72‑hour reporting expectation requires organizations to have mature incident detection and escalation processes, which many do not yet possess.Vietnam PDPL overview – Uniconsent
  • Implementation guides explain that organizations must coordinate IT, legal, and compliance teams to meet PDPL timelines and documentation expectations.Data protection laws in Vietnam – DLA Piper overview
  • EY notes, in the context of Decree 13 and related regulations, that technical and managerial measures for protection must be in place, which often remain incomplete in practice.EY Vietnam legal update on Decree 13

Implementation Best Practices

Below are actionable steps and related guidance to help organizations implement PDPL compliance.

  • Conduct a comprehensive data mapping and classification exercise
  • Identify all personal data your organization processes, including customer, employee, vendor, and user data; classify general vs sensitive data categories.Vietnam PDPL – compliance steps (Rouse)
  • Map data flows within Vietnam and cross‑border, including transfers to parent companies, cloud providers, and third‑party service providers.Data protection laws in Vietnam – DLA Piper overview
  • Use PDPL‑focused checklists and templates provided by consult

Recent developments

  • — Asia Counsel’s 2026 Data Protection Guide explains that the **Personal Data Protection Law No. 91/2025/QH15 (PDPL)** became the primary instrument regulating personal data activities in Vietnam from 2026-01-01, superseding Decree 13 and detailing key compliance obligations and enforcement risks.[14] (source)
  • — LuatVietnam’s August 2026 legal update outlines the structure of **Law No. 91/2025/QH15** (5 chapters, 39 articles), confirms its effective date of 2026-01-01, and summarizes main provisions on personal data classification, data subject rights, and obligations for controllers and processors.[1] (source)
  • — The Future of Privacy Forum’s updated issue brief (legislative update reflected as of January 2026) analyzes how **Decree No. 356/2025/ND-CP** implements the PDP Law, highlighting detailed rules on consent, cross-border transfers, enforcement mechanisms, and the overall governance regime for personal data in Vietnam.[15] (source)
  • — Tilleke & Gibbins’ March 2026 analysis (updated August 2026) provides a “closer look” at Vietnam’s PDPL, emphasizing its extraterritorial reach to foreign entities processing data of Vietnamese citizens, new enforcement powers, and the compliance burden on multinational companies operating in or targeting Vietnam.[8] (source)
  • — DLA Piper’s Vietnam data protection overview (updated in 2026) notes that **Law No. 91/2025/QH15** elevated data protection from decree-level to statutory law, explains its alignment and differences with Decree 13, and discusses practical compliance expectations for businesses, including consent, DPIA, and data breach notification requirements.[4] (source)
  • — FPF’s issue brief (prepared around the law’s entry into force and updated for early 2026) provides a detailed policy analysis of Vietnam’s new data protection and governance regime, including PDP Law No. 91/2025/QH15, describing regulatory structure, sectoral rules, and anticipated enforcement trends.[10] (source)
  • — ACSV Legal’s note on **Decree No. 356/2025/ND-CP** explains that the decree, issued on 2025-12-31 and effective from 2026-01-01 together with Law No. 91/2025/QH15, formally transitions Vietnam from Decree 13/2023/ND-CP to a higher-level statutory framework and details implementation of key PDP Law provisions.[9] (source)
  • — Simuna Infosec’s June 2026 blog update on **Vietnam PDPL 2025 (Law 91/2025/QH15)** discusses differing published views on the law’s effective date, summarizes security and governance requirements, and flags compliance challenges for organizations needing to reconcile transitional expectations with the new statutory regime.[6] (source)
  • — A January 2026 LuatVietnam legal update confirms that the PDP Law took effect on 2026-01-01 and provides an overview of its application scope, categories of personal data, and basic rights and obligations, serving as an early guidance resource for regulated entities.[1] (source)
  • — FPF’s January 2026 blog post announcing its updated issue brief on Vietnam’s Law on Protection of Personal Data and related data laws highlights that the PDP Law is expected to apply from 2026-01-01 and discusses implications for cross-border data flows, governance, and civil society concerns about implementation.[7] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates