Law note · Vietnam

Law on Personal Data Protection, biometric and location data protection

cite Law No. 91/2025/QH15, Article 31 stage RECENT in force 8 months effective 2026-01-01 kind Biometric privacy binds private bodies reviewed 2026-08-29

What it requires

  • An app that collects or processes biometric data, meaning physical attributes and unique, stable biological characteristics used to identify a person, from an individual in Vietnam must apply physical security measures, limit access, and maintain a monitoring system to detect infringement, and is liable for damage its processing causes.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • trains_models
  • crawls_web

What we found

Article 31 defines biometric data as data on physical attributes and unique and stable biological characteristics of a person used to identify that person, and requires an organization, agency, or individual collecting or processing biometric data to apply physical security measures for storage and transmission devices, limit access, maintain a monitoring system to detect infringement, and comply with relevant laws and international standards; a processor causing damage through biometric-data processing is liable.

Unlike every other jurisdiction in this research batch, Article 31 names no facial, voice, or fingerprint example at all, resting entirely on the general physical-attribute language; whether the definition excludes an identifier derived from a photo, video, or audio recording is accordingly recorded as unresolved rather than confirmed either way.

This provision functions as heightened, category-wide protection rather than a named consent-at-capture rule distinct from the Law's general Article 8 consent duty, which was not read verbatim this pass.

Primary source

Government Portal (chinhphu.vn) citation
substantive text read via a private secondary translation (LuatVietnam)

← Back to the example  ·  Lint your app →