Vietnam's New Data Privacy Frontier: A Comprehensive Guide to Law No. 91/2025/QH15
Legal Disclaimer: This article provides a general overview of Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15) for informational purposes only. It does not constitute legal advice. Organizations should consult with local legal counsel to ensure specific compliance with Vietnamese regulations.
As of January 1, 2026, Vietnam has officially signaled its entry into the premier league of data governance with the enforcement of Law No. 91/2025/QH15 on Personal Data Protection.
For multinational corporations, this is the moment where operational expansion in Southeast Asia must meet rigorous compliance.
Extraterritorial Reality: The Border is No Shield
Vietnam's new law follows the "Brussels Effect." It doesn't matter where your headquarters are; if you process the personal data of Vietnamese citizens or residents, you are now legally bound by this framework. Vietnam has joined the ranks of jurisdictions that project their privacy standards globally, demanding accountability from any entity touching its citizens' data.
The New Hierarchy: Basic vs. Sensitive Data
The law enforces a clear distinction that dictates your level of security and administrative overhead:
- Basic Personal Data: Names, contact details, and common social identifiers.
- Sensitive Personal Data: A high-risk category including health records, private life details, and biometric data. Processing sensitive data now triggers the most stringent protection requirements and carries the highest legal exposure in the event of a breach.
Consent: The End of "Opt-Out" and Silence
Article 9 is now live: consent must be voluntary, informed, and given for each specific purpose. The law is crystal clear that silence or non-response is not consent. If your user interface relies on pre-checked boxes or "assumed consent" for Vietnamese users, your organization is likely in breach as of this week.
Immediate Action: Impact Assessments (DPIA)
The administrative clock is ticking. Under Article 21, organizations must maintain and submit a Personal Data Processing Impact Assessment (DPIA) dossier to the specialized agency.
- This is a mandatory filing that must be completed within 60 days of beginning processing.
- Under Article 22, these dossiers must be updated every 6 months when there is a change, and immediately in certain cases such as a reorganization or a new business line.
Cross-Border Transfers: 5% of Revenue at Stake
The most critical risk factor in Q1 2026 is Article 20. Moving data outside Vietnam now requires a formal Cross-Border Transfer Impact Assessment.
- The Enforcement: Violations regarding cross-border flows can result in administrative fines of up to 5% of an organization's total revenue from the preceding year.
- The specialized agency now holds the authority to suspend data transfers that threaten national security or other national interests.
Navigating the 2026 Regulatory Landscape
While small enterprises and startups may navigate a limited five-year grace period for the impact assessment filings in Articles 21 and 22 (Article 38), the core principles of data protection and the risk of massive revenue-based fines are an immediate reality for the rest of the market.
The priority for the first half of 2026 is clear: Move beyond the old decree-based compliance. Vietnam's emergence as a global economic power means its regulators are no longer observing from the sidelines, they are active participants in the global data privacy conversation.
This article is general information from Data Protection Matters, not legal advice. We aim to be accurate, but it may contain errors or omissions and we give no warranty as to its accuracy or completeness. It reflects the position at the time of writing; privacy laws change and vary by jurisdiction. Verify against official sources, seek advice for your own situation, and rely on it at your own risk.
