Published: August 10, 2026 | Last updated: August 10, 2026 | Author: DataCore Research | Publisher: DataCore
TL;DR
- The Vietnam data protection law, officially Law No. 91/2025/QH15 on Personal Data Protection (Vietnamese: Luật Bảo vệ dữ liệu cá nhân), takes effect January 1, 2026, and sets fines from 1% to 5% of an organization's prior-year revenue for personal data violations (Article 4; source: LSVN, July 15, 2025).
- Article 8, as broken down by legal advisory firm Sunteco (August 4, 2026), sets three concrete penalty tiers under the Vietnam data protection law: illegal data trading (up to 10x illicit gain or 3 billion VND), unlawful cross-border transfer (up to 5% of prior-year revenue or 3 billion VND), and other violations such as missing consent mechanisms (up to 3 billion VND flat).
- Vietnam's Ministry of Public Security (Vietnamese: Bộ Công An) reported 56 cases of illegal personal data trading in H1 2025, involving more than 110 million records (source: VnEconomy, citing the ministry's mid-2025 briefing).

What is Vietnam's new Personal Data Protection Law?
The Vietnam data protection law is the country's first comprehensive statute governing how organizations collect, process, store, and transfer personal data. Formally titled Law No. 91/2025/QH15, it was passed by the National Assembly and takes effect on January 1, 2026. The law replaces a patchwork of decree-level rules that previously governed data privacy in Vietnam, consolidating consent requirements, breach obligations, and cross-border transfer rules into a single piece of legislation with real financial teeth.
Under the Vietnam data protection law, "personal data" covers any information that can identify a specific individual, whether directly (such as a national ID number) or indirectly (such as a device identifier combined with location history). The law applies to every organization or individual that processes personal data of Vietnamese citizens, including companies headquartered outside Vietnam if their processing activities touch Vietnamese data subjects. That extraterritorial reach mirrors the approach taken by Europe's GDPR, and it means foreign fintech, e-commerce, and SaaS companies serving Vietnamese users cannot treat the Vietnam data protection law as a domestic-only concern.
How large are the fines under Article 4?
Article 4 of Law No. 91/2025/QH15 sets administrative fines at 1% to 5% of an organization's prior-year revenue for violations of personal data protection obligations, according to the verbatim text quoted by LSVN on July 15, 2025. This revenue-based fine structure is the single most consequential feature of the Vietnam data protection law for large enterprises, because it scales the penalty to company size rather than capping it at a fixed amount.
This revenue-based fine structure mirrors the approach used in Europe's GDPR and marks a sharp escalation from Vietnam's earlier decree-level penalties, which were capped at fixed VND amounts regardless of company size. For a large fintech or bank, a 5% revenue fine can run into hundreds of billions of VND. That is why compliance teams should not wait until January 2026 to start closing consent and data-handling gaps under the Vietnam data protection law: revenue-scaled fines mean the cost of inaction grows every quarter the company keeps operating at its current size without remediation.

What are the three penalty tiers under Article 8?
Legal advisory firm Sunteco published a detailed breakdown of Article 8 on August 4, 2026, splitting the Vietnam data protection law's enforcement structure into three distinct penalty tiers. The first tier covers illegal data trading, which carries a fine of up to 10 times the illicit gain or 3 billion VND, whichever is higher. The second tier covers unlawful cross-border data transfer, which is capped at 5% of prior-year revenue or 3 billion VND.
The third tier is a catch-all for other violations, such as missing or invalid consent mechanisms and inadequate security controls. These violations carry a flat fine of up to 3 billion VND. Individual violators, as opposed to organizations, face fines of up to half the organizational maximum in each tier under the Vietnam data protection law (source: Sunteco, August 4, 2026). Businesses should map each of their data-handling workflows against these three tiers now, since the classification of a given violation determines which cap applies.
How much illegal data trading has Vietnam already found?
The scale of the problem the Vietnam data protection law is responding to is already well documented. Vietnam's Ministry of Public Security (Vietnamese: Bộ Công An), the country's national police and internal security agency, reported detecting 56 cases of illegal personal data trading in the first half of 2025 (H1 2025), involving more than 110 million records, according to the ministry's mid-2025 press briefing as reported by VnEconomy.
That volume of exposed records is roughly equivalent to Vietnam's entire population. It is the backdrop against which the National Assembly passed Law No. 91/2025/QH15 a matter of weeks later. The scale of that breach data is a large part of why the Vietnam data protection law leans so heavily on revenue-based fines rather than fixed penalties: fixed fines had visibly failed to deter data trading at the volume the ministry documented.

Is a separate digital identity law also coming?
Yes. On May 11, 2026, a draft Law on Digital Identity and Authentication was added to Vietnam's 2026 legislative program via Resolution 125/NQ-CP. It would be Vietnam's first dedicated law on digital identity and VNeID authentication (source: Bao Chinh Phu, May 11, 2026). Once passed, it is expected to work alongside the Vietnam data protection law rather than replace it, with the identity law governing authentication flows and the data protection law governing how any personal data collected during authentication is stored, processed, and transferred.
For businesses that already rely on eKYC (electronic Know Your Customer) processes, this pairing matters: identity verification data collected today under existing practice will need to comply with both the digital identity framework once it passes and the Vietnam data protection law's consent and security requirements, which are already in effect from January 1, 2026.
What should businesses do before January 1, 2026?
Three things matter most in the run-up to the Vietnam data protection law's effective date. First, publish or update a privacy policy that meets the law's consent and disclosure requirements, since a missing or invalid consent mechanism falls under the Article 8 catch-all tier with fines up to 3 billion VND.
Second, review any cross-border data transfer arrangements, such as cloud infrastructure or data processing agreements hosted outside Vietnam, since unlawful transfers carry a fine of up to 5% of prior-year revenue under the Vietnam data protection law. Third, harden the identity verification layer, since weak security controls that lead to a breach are explicitly named as a violation under Article 8.
This is where a properly configured eKYC process earns its keep: it verifies customer identity through a documented, auditable flow rather than an ad hoc manual check, which is exactly the kind of control regulators look for when assessing whether "reasonable security measures" were in place at the time of an incident. Companies that treat Vietnam data protection law compliance as a one-time checklist item, rather than an ongoing program, are the ones most likely to be caught out when the Ministry of Public Security's enforcement activity ramps up after the January 2026 effective date.

How does Vietnam's data protection law compare to other frameworks in the region?
The Vietnam data protection law is not the first of its kind in Southeast Asia, but it is one of the strictest in terms of financial penalties. Singapore's Personal Data Protection Act caps fines at 10% of annual turnover in Singapore or 1 million Singapore dollars, whichever is higher, for the most serious breaches. Thailand's Personal Data Protection Act relies mainly on fixed fines and criminal liability for individual executives rather than a straight revenue percentage. Against that backdrop, the Vietnam data protection law's 1% to 5% of prior-year revenue formula sits closer to the European Union's GDPR model, which caps fines at up to 4% of global annual turnover for the most serious infringements.
For a multinational company already building GDPR or Singapore PDPA compliance programs, the Vietnam data protection law does not require starting from zero. Consent management, data subject access request handling, and breach notification workflows built for GDPR translate reasonably well to the Vietnam data protection law's requirements. The gaps most compliance teams find are around data localization and cross-border transfer approval, since Vietnam's rules on where personal data can be processed and stored are more prescriptive than the GDPR's adequacy-decision model.
What data breach notification timeline does the law set?
The Vietnam data protection law requires organizations to notify Vietnam's data protection authority of a personal data breach within 72 hours of discovery, in line with the notification window used by the GDPR. The notification must describe the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed to address the breach.
Where the breach is likely to result in a high risk to the rights of affected individuals, the Vietnam data protection law also requires direct notification to those individuals, not just the regulator. Compliance teams building an incident response plan around the Vietnam data protection law should treat the 72-hour clock as starting from the moment internal security teams confirm a breach has occurred, not from the moment it is fully investigated, since the law does not extend the deadline for an ongoing investigation.
Which industries face the highest compliance burden?
Banks, fintech platforms, and telecom operators carry the highest exposure under the Vietnam data protection law, simply because they process the largest volumes of sensitive personal data, including financial transaction history, credit information, and biometric identifiers used for eKYC. For these sectors, a single Article 4 violation calculated at 5% of prior-year revenue can represent a nine-figure or ten-figure VND sum, which is why several large Vietnamese banks have already begun independent data protection audits ahead of the January 2026 effective date.
E-commerce marketplaces and delivery platforms are a close second, since they combine payment data with granular location and behavioral data. Any platform that shares user data with third-party advertising networks or analytics vendors should specifically review whether those data-sharing arrangements qualify as a transfer under the Vietnam data protection law, since Article 8's cross-border transfer tier applies even when the data leaves Vietnam only briefly for processing before returning.
What penalties apply to individual violators versus organizations?
The Vietnam data protection law draws a clear line between organizational and individual liability. Organizations face the full fine schedule described in Articles 4 and 8, calculated as a percentage of revenue or a flat VND amount depending on the violation tier. Individuals acting outside the scope of an organization, such as a freelance data broker, face fines capped at half the organizational maximum for the equivalent violation.
This distinction matters for company directors and compliance officers specifically: the Vietnam data protection law does not automatically extend organizational fines to individual employees who were following company policy, but employees who act outside their authorized role, such as an employee who exports a customer database for personal resale, can be individually liable under the same Article 8 tiers that apply to illegal data trading.
One more practical difference worth flagging: unlike the GDPR, which lets companies self-assess "legitimate interest" as a legal basis for processing in many cases, the Vietnam data protection law leans more heavily on explicit, opt-in consent as the default basis for processing. Companies migrating a GDPR-based consent flow into the Vietnamese market under the Vietnam data protection law should audit whether their existing consent language and opt-in mechanics meet this stricter default, rather than assuming a GDPR-compliant flow is automatically sufficient.
Businesses that operate call centers, customer support chat, or CRM systems handling Vietnamese customer records should also note that the Vietnam data protection law treats voice recordings and chat transcripts as personal data when they can be linked to an identifiable individual, which most CRM and support-ticket systems can do by default through phone number or account matching. Reviewing retention periods for these records against the law's data minimization principle is a practical first step many DataCore clients are taking now, ahead of the January 2026 effective date.
FAQ
What is the Vietnam data protection law?
The Vietnam data protection law is Law No. 91/2025/QH15 on Personal Data Protection, which takes effect January 1, 2026 and sets fines from 1% to 5% of an organization's prior-year revenue for violations (Article 4; source: LSVN, July 15, 2025).
What are the three penalty tiers under Article 8 of the Vietnam data protection law?
Article 8 breaks this down further: cross-border transfer violations cap at 5% of revenue, illegal data trading caps at 10x the illicit gain (or 3 billion VND), and other violations cap at a flat 3 billion VND (sources: LSVN, July 15, 2025; Sunteco, August 4, 2026).
Does the Vietnam data protection law apply to foreign companies?
Yes. Law No. 91/2025/QH15 applies to any organization or individual processing personal data of Vietnamese citizens, regardless of where that organization is headquartered.
How many personal data trading cases has Vietnam found so far?
Vietnam's Ministry of Public Security reported 56 cases of illegal personal data trading in H1 2025, involving more than 110 million records (source: VnEconomy, citing the ministry's mid-2025 briefing).
Is there a related law on digital identity?
Yes. A draft Law on Digital Identity and Authentication was added to Vietnam's 2026 legislative program on May 11, 2026 via Resolution 125/NQ-CP. It would be Vietnam's first dedicated law on digital identity and VNeID authentication (source: Bao Chinh Phu, May 11, 2026).
What can businesses do now to prepare for the Vietnam data protection law?
Publish a compliant privacy policy with a valid consent mechanism, review any cross-border data transfer arrangements, and strengthen identity verification controls, such as a documented eKYC process, before the law's January 1, 2026 effective date.
What is the data breach notification deadline under the Vietnam data protection law?
Organizations must notify Vietnam's data protection authority within 72 hours of discovering a breach, and notify affected individuals directly if the breach poses a high risk to their rights.
Which industries face the highest compliance burden under the Vietnam data protection law?
Banks, fintech platforms, telecom operators, and e-commerce marketplaces face the highest exposure, since they process the largest volumes of financial, biometric, and location data.
Sources
- LSVN, "Xam pham du lieu ca nhan co the bi phat toi da den 5% doanh thu nam lien ke," July 15, 2025
- Sunteco, "Muc phat vi pham du lieu ca nhan 2026," August 4, 2026
- VnEconomy, "Xam pham du lieu ca nhan co the bi phat toi da den 5% doanh thu nam lien ke"
- Bao Chinh Phu (Báo Chính Phủ), "Bo sung du an Luat dinh danh va xac thuc dien tu vao chuong trinh lap phap nam 2026," May 11, 2026







Để lại một bình luận
You must be logged in to post a comment.