Vietnam's Data Protection Law: Compliance Checklist for Foreign Firms
Vietnam's Personal Data Protection Law took effect in 2026. Our practical checklist shows foreign companies what to fix first - and what can wait.

Vietnam has completed its journey from light-touch data regulation to a comprehensive regime. The Personal Data Protection Law (PDPL), passed in 2025 and in force from the start of 2026, elevates the rules first introduced by the 2023 personal data protection decree into full legislation - with broader scope, harder obligations and real penalties. If your company processes data about people in Vietnam - customers, employees, app users, marketing leads - this law applies to you, whether or not you have a Vietnamese entity. Here is the compliance checklist we walk foreign clients through.
First, confirm you are in scope
The PDPL reaches further than many foreign executives assume. It covers Vietnamese organizations, foreign-invested entities in Vietnam, and offshore companies that process personal data of individuals in Vietnam. An e-commerce seller shipping into Vietnam, a SaaS product with Vietnamese users, or a regional HR shared-services center handling Vietnamese payroll are all plausibly in scope. There is no meaningful revenue threshold that exempts small operations, although some obligations are eased for small businesses and startups for an initial period - check the current exemptions with your advisor, as implementing guidance continues to develop.
The obligations that bite hardest
1. Consent, done Vietnam's way
Vietnam's regime is consent-centric. Consent must be explicit, informed, specific to purpose, and demonstrable - silence and pre-ticked boxes do not count. Practically, this means auditing every point where you collect personal data (web forms, apps, sales calls, HR onboarding) and confirming you can evidence what a person agreed to and when. Bundled catch-all consents are the single most common failure we find in audits.
2. Sensitive data gets a higher gear
Health, financial, biometric, location and similar categories are treated as sensitive personal data, requiring additional notice to the individual and stricter handling. Employers routinely hold sensitive data - medical certificates, bank details, union membership - often without realizing it triggers heightened duties.
3. Impact assessment dossiers
Organizations processing personal data must prepare and maintain a processing impact assessment dossier, and those transferring data out of Vietnam need a cross-border transfer dossier, kept available for the Ministry of Public Security's data protection authority. These are not one-off filings; they must be updated as your processing changes. Timelines for preparing and submitting dossiers have specific deadlines from the start of processing - confirm the current windows with counsel.
4. Cross-border transfers
Offshoring Vietnamese personal data - to a regional headquarters, a global CRM, a cloud provider - is permitted but regulated. You need the transfer dossier, appropriate disclosures, and a clear map of where data actually flows. Multinationals with centralized IT stacks feel this obligation most.
5. Rights handling and breach response
Individuals hold rights to access, correct, delete and withdraw consent, and companies must be able to respond within regulated timeframes. Data breaches must be notified to the authorities quickly - the statutory window is short, so a pre-agreed internal escalation path is essential.
6. Prohibited practices
The law flatly prohibits buying and selling personal data. Marketing teams acquiring "lead lists" from brokers are the classic trap here; that practice must stop.
Priority matrix for foreign companies
| Action | Urgency | Typical owner | Notes |
|---|---|---|---|
| Data mapping: what you hold, where it flows | Immediate | Legal + IT | Prerequisite for everything else |
| Consent capture audit and remediation | Immediate | Marketing, HR, Product | Fix bundled and implied consents |
| Impact assessment + cross-border dossiers | High | Legal / DPO | Keep updated; deadlines apply from processing start |
| Appoint data protection personnel/DPO | High | Management | Requirements vary by scale and data sensitivity - verify current rules |
| Vendor and processor contracts | High | Legal + Procurement | Flow down PDPL obligations to processors |
| Breach response playbook | Medium | IT security + Legal | Short notification window; rehearse it |
| Employee privacy notices and training | Medium | HR | HR data is fully in scope |
How this compares to GDPR - and why that matters
Companies with mature GDPR programs start ahead but are not finished. The overlap is substantial: lawful processing, purpose limitation, individual rights, breach notification. The differences are where risk hides. Vietnam leans harder on consent than on "legitimate interests" style bases; the dossier system is a distinct administrative mechanism with its own formats and its own regulator; and Vietnamese-language documentation matters in practice when dealing with authorities. Mapping your GDPR artifacts onto PDPL requirements is efficient, but a copy-paste of the EU program will leave gaps.
Penalties and enforcement posture
Administrative fines can be substantial - for certain violations, sanction frameworks have contemplated penalties scaled to revenue, alongside suspension of processing activities. Early enforcement typically concentrates on egregious cases: data trading, large breaches, refusal to cooperate. But foreign-invested companies should not bet on obscurity; sectors handling large consumer datasets - e-commerce, fintech, retail, hospitality - are the natural first targets for inspections. Check current penalty levels with your advisor rather than relying on secondary summaries.
A pragmatic 90-day plan
- Days 1–30: data inventory and flow mapping; identify cross-border transfers; nominate an internal owner.
- Days 31–60: remediate consent mechanisms; draft impact assessment and transfer dossiers; update privacy notices in Vietnamese and English.
- Days 61–90: processor contract amendments; breach playbook and training; management sign-off and calendar for periodic dossier updates.
Perfection is not achievable in one quarter, but documented, good-faith progress materially changes how authorities engage with you.
Need help getting PDPL-ready? Our compliance team in Vietnam builds data protection dossiers, consent frameworks and ongoing compliance calendars for foreign-invested companies - talk to us before the first inspection letter, not after.


