Vietnam's Data Protection Law: Compliance Checklist for Foreign Firms

Vietnam's Personal Data Protection Law took effect in 2026. Our practical checklist shows foreign companies what to fix first - and what can wait.

4 min read
Vietnam's Data Protection Law: Compliance Checklist for Foreign Firms

Vietnam has completed its journey from light-touch data regulation to a comprehensive regime. The Personal Data Protection Law (PDPL), passed in 2025 and in force from the start of 2026, elevates the rules first introduced by the 2023 personal data protection decree into full legislation - with broader scope, harder obligations and real penalties. If your company processes data about people in Vietnam - customers, employees, app users, marketing leads - this law applies to you, whether or not you have a Vietnamese entity. Here is the compliance checklist we walk foreign clients through.

First, confirm you are in scope

The PDPL reaches further than many foreign executives assume. It covers Vietnamese organizations, foreign-invested entities in Vietnam, and offshore companies that process personal data of individuals in Vietnam. An e-commerce seller shipping into Vietnam, a SaaS product with Vietnamese users, or a regional HR shared-services center handling Vietnamese payroll are all plausibly in scope. There is no meaningful revenue threshold that exempts small operations, although some obligations are eased for small businesses and startups for an initial period - check the current exemptions with your advisor, as implementing guidance continues to develop.

The obligations that bite hardest

Vietnam's regime is consent-centric. Consent must be explicit, informed, specific to purpose, and demonstrable - silence and pre-ticked boxes do not count. Practically, this means auditing every point where you collect personal data (web forms, apps, sales calls, HR onboarding) and confirming you can evidence what a person agreed to and when. Bundled catch-all consents are the single most common failure we find in audits.

2. Sensitive data gets a higher gear

Health, financial, biometric, location and similar categories are treated as sensitive personal data, requiring additional notice to the individual and stricter handling. Employers routinely hold sensitive data - medical certificates, bank details, union membership - often without realizing it triggers heightened duties.

3. Impact assessment dossiers

Organizations processing personal data must prepare and maintain a processing impact assessment dossier, and those transferring data out of Vietnam need a cross-border transfer dossier, kept available for the Ministry of Public Security's data protection authority. These are not one-off filings; they must be updated as your processing changes. Timelines for preparing and submitting dossiers have specific deadlines from the start of processing - confirm the current windows with counsel.

4. Cross-border transfers

Offshoring Vietnamese personal data - to a regional headquarters, a global CRM, a cloud provider - is permitted but regulated. You need the transfer dossier, appropriate disclosures, and a clear map of where data actually flows. Multinationals with centralized IT stacks feel this obligation most.

5. Rights handling and breach response

Individuals hold rights to access, correct, delete and withdraw consent, and companies must be able to respond within regulated timeframes. Data breaches must be notified to the authorities quickly - the statutory window is short, so a pre-agreed internal escalation path is essential.

6. Prohibited practices

The law flatly prohibits buying and selling personal data. Marketing teams acquiring "lead lists" from brokers are the classic trap here; that practice must stop.

Priority matrix for foreign companies

ActionUrgencyTypical ownerNotes
Data mapping: what you hold, where it flowsImmediateLegal + ITPrerequisite for everything else
Consent capture audit and remediationImmediateMarketing, HR, ProductFix bundled and implied consents
Impact assessment + cross-border dossiersHighLegal / DPOKeep updated; deadlines apply from processing start
Appoint data protection personnel/DPOHighManagementRequirements vary by scale and data sensitivity - verify current rules
Vendor and processor contractsHighLegal + ProcurementFlow down PDPL obligations to processors
Breach response playbookMediumIT security + LegalShort notification window; rehearse it
Employee privacy notices and trainingMediumHRHR data is fully in scope

How this compares to GDPR - and why that matters

Companies with mature GDPR programs start ahead but are not finished. The overlap is substantial: lawful processing, purpose limitation, individual rights, breach notification. The differences are where risk hides. Vietnam leans harder on consent than on "legitimate interests" style bases; the dossier system is a distinct administrative mechanism with its own formats and its own regulator; and Vietnamese-language documentation matters in practice when dealing with authorities. Mapping your GDPR artifacts onto PDPL requirements is efficient, but a copy-paste of the EU program will leave gaps.

Penalties and enforcement posture

Administrative fines can be substantial - for certain violations, sanction frameworks have contemplated penalties scaled to revenue, alongside suspension of processing activities. Early enforcement typically concentrates on egregious cases: data trading, large breaches, refusal to cooperate. But foreign-invested companies should not bet on obscurity; sectors handling large consumer datasets - e-commerce, fintech, retail, hospitality - are the natural first targets for inspections. Check current penalty levels with your advisor rather than relying on secondary summaries.

A pragmatic 90-day plan

  1. Days 1–30: data inventory and flow mapping; identify cross-border transfers; nominate an internal owner.
  2. Days 31–60: remediate consent mechanisms; draft impact assessment and transfer dossiers; update privacy notices in Vietnamese and English.
  3. Days 61–90: processor contract amendments; breach playbook and training; management sign-off and calendar for periodic dossier updates.

Perfection is not achievable in one quarter, but documented, good-faith progress materially changes how authorities engage with you.

Need help getting PDPL-ready? Our compliance team in Vietnam builds data protection dossiers, consent frameworks and ongoing compliance calendars for foreign-invested companies - talk to us before the first inspection letter, not after.

ShareLinkedInEmail

Related insights

Accounting & Tax Compliance Services4 min read

Corporate Tax Planning in Vietnam: The Legitimate Levers

Where the real levers are - deductibility, incentives, loss carry-forward, related-party substance, treaty relief and funding structure - and the patterns that reliably attract an audit.

Accounting & Tax Compliance Services4 min read

Compliance Obligations of a Foreign-Owned Company in Vietnam

Tax is roughly a third of it. The full map across five domains - tax, accounting, labour, insurance and licence maintenance - and the steps that quietly add new obligations as you grow.

Book a ConsultationCall