Law / Vietnam

Vietnam

privacy

Vietnam's first standalone, comprehensive personal-data statute is the Law on Personal Data Protection, Law No. 91/2025/QH15, passed by the 15th National Assembly at its 9th session on 26 June 2025 and in force since 1 January 2026, replacing Decree 13/2023/ND-CP, which was itself only a government decree rather than a National Assembly law. Two derived corpus candidates disagree on the operative law's number: one cites 34/2025/QH15, the other 91/2025/QH15.

This document follows the correct number, 91/2025/QH15, confirmed against the Government Portal's own page title for the enactment and the Ministry of Public Security's commencement announcement; the 34/2025/QH15 candidate is not folded into this document's corpus_codes as the same law.

The official signed PDF of the Law did not extract cleanly through crawler infrastructure (a PDF.js viewer capture rather than document text), so the article-level text in this document was read through a private secondary publisher's English translation rather than the government's own text; re-verification against a clean extraction of the primary PDF is still needed.

Article 31's biometric data definition names no facial or voice examples at all, unlike every other jurisdiction in this research batch, resting entirely on general physical-attribute language, so the biometric definition's exact reach to a recording-derived identifier is recorded as unresolved rather than confirmed either way.

A companion implementing decree, Decree 356/2025/ND-CP, took effect alongside the Law on the same date but was not independently read this pass and is not otherwise represented in this document.

16 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Law on Personal Data Protection, biometric and location data protection

cite Law No. 91/2025/QH15, Article 31 stage RECENT in force 8 months effective 2026-01-01 binds private bodies source Government Portal (chinhphu.vn) citation
What it requires

Article 31 defines biometric data as data on physical attributes and unique and stable biological characteristics of a person used to identify that person, and requires an organization, agency, or individual collecting or processing biometric data to apply physical security measures for storage and transmission devices, limit access, maintain a monitoring system to detect infringement, and comply with relevant laws and international standards; a processor causing damage through biometric-data processing is liable.

Unlike every other jurisdiction in this research batch, Article 31 names no facial, voice, or fingerprint example at all, resting entirely on the general physical-attribute language; whether the definition excludes an identifier derived from a photo, video, or audio recording is accordingly recorded as unresolved rather than confirmed either way.

This provision functions as heightened, category-wide protection rather than a named consent-at-capture rule distinct from the Law's general Article 8 consent duty, which was not read verbatim this pass.

Breach notification

Law on Personal Data Protection, breach notification

cite Law No. 91/2025/QH15, Article 23 stage RECENT in force 8 months effective 2026-01-01 binds private bodies source Government Portal (chinhphu.vn) citation
What it requires

Article 23 requires the personal data controller, the personal data controlling and processing party, or a third party to notify the agency in charge of personal data protection within 72 hours after detecting a violation likely to cause harm to national defense and security and social order and safety, or to infringe upon the life, health, honor, dignity, or property of the personal data subject.

Where a personal data processor detects a violation, it must promptly notify the controller or the controlling and processing party.

Comprehensive regime

Law on Personal Data Protection, comprehensive regime

cite Law No. 91/2025/QH15, passed by the 15th National Assembly, 9th session, 26 June 2025, in force 1 January 2026 stage RECENT in force 8 months effective 2026-01-01 binds private bodies source Government Portal (chinhphu.vn) citation
What it requires

The Law on Personal Data Protection (Law No. 91/2025/QH15) is Vietnam's first standalone, comprehensive personal-data statute, replacing Decree 13/2023/ND-CP, which was itself Vietnam's first general personal-data instrument but only a government decree rather than a National Assembly law. A companion implementing decree, Decree 356/2025/ND-CP, took effect alongside the Law on the same date; it was not independently read this pass.

The Law's commencement date is confirmed via the Ministry of Public Security's own portal, a government source; the government's own signed PDF of the Law did not extract cleanly through crawler infrastructure, so the substantive article text in this document comes from a private secondary publisher's English translation (LuatVietnam) rather than the government's own text, and re-verification against a clean extraction of the primary PDF is still needed.

A derived corpus candidate citing this same enactment as Law No. 34/2025/QH15 is incorrect, per the Government Portal's own page title and the Ministry of Public Security's announcement, and is not folded into this document as the same law.

Cross border transfer

Law on Personal Data Protection, cross-border transfer

cite Law No. 91/2025/QH15, Article 20 stage RECENT in force 8 months effective 2026-01-01 binds private bodies source Government Portal (chinhphu.vn) citation
What it requires

Article 20 enumerates the cases in which cross-border transfer of personal data is permitted; its substantive conditions, including any adequacy standard, government approval requirement, or data-localization element, were not read beyond the article's heading and opening clause this pass.

A separate penalties article confirms a materially strict enforcement posture: the maximum fine for an organization violating cross-border transfer regulations specifically is 5 percent of the organization's prior-year revenue, distinct from and higher than the Law's general violation fine tier.

Enforcement supervision

Law on Personal Data Protection, enforcement and data subject rights

cite Law No. 91/2025/QH15, enforcement and data subject rights provisions stage RECENT in force 8 months effective 2026-01-01 binds private bodies source Government Portal (chinhphu.vn) citation
What it requires

The Law names an agency in charge of personal data protection as the enforcement authority, without independently confirming the specific body's name this pass, though the Ministry of Public Security's role publicizing the Law's commencement suggests it sits under that ministry.

Administrative fines confirmed directly reach up to 5 percent of the prior year's organizational revenue for cross-border transfer violations specifically, with a separate, lower general fine tier referenced elsewhere in the same penalties article and not read in full.

A data-subject-rights clause confirms individuals may request the provision and deletion of their personal data, restriction of processing, and may object to processing, and separately may file complaints and denunciations, initiate lawsuits, and request compensation for damage in accordance with law, arming a private plaintiff.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.