Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
What it requires →
Article 31 defines biometric data as data on physical attributes and unique and stable biological characteristics of a person used to identify that person, and requires an organization, agency, or individual collecting or processing biometric data to apply physical security measures for storage and transmission devices, limit access, maintain a monitoring system to detect infringement, and comply with relevant laws and international standards; a processor causing damage through biometric-data processing is liable.
Unlike every other jurisdiction in this research batch, Article 31 names no facial, voice, or fingerprint example at all, resting entirely on the general physical-attribute language; whether the definition excludes an identifier derived from a photo, video, or audio recording is accordingly recorded as unresolved rather than confirmed either way.
This provision functions as heightened, category-wide protection rather than a named consent-at-capture rule distinct from the Law's general Article 8 consent duty, which was not read verbatim this pass.
Breach notification
What it requires →
Article 23 requires the personal data controller, the personal data controlling and processing party, or a third party to notify the agency in charge of personal data protection within 72 hours after detecting a violation likely to cause harm to national defense and security and social order and safety, or to infringe upon the life, health, honor, dignity, or property of the personal data subject.
Where a personal data processor detects a violation, it must promptly notify the controller or the controlling and processing party.
Comprehensive regime
What it requires →
The Law on Personal Data Protection (Law No. 91/2025/QH15) is Vietnam's first standalone, comprehensive personal-data statute, replacing Decree 13/2023/ND-CP, which was itself Vietnam's first general personal-data instrument but only a government decree rather than a National Assembly law. A companion implementing decree, Decree 356/2025/ND-CP, took effect alongside the Law on the same date; it was not independently read this pass.
The Law's commencement date is confirmed via the Ministry of Public Security's own portal, a government source; the government's own signed PDF of the Law did not extract cleanly through crawler infrastructure, so the substantive article text in this document comes from a private secondary publisher's English translation (LuatVietnam) rather than the government's own text, and re-verification against a clean extraction of the primary PDF is still needed.
A derived corpus candidate citing this same enactment as Law No. 34/2025/QH15 is incorrect, per the Government Portal's own page title and the Ministry of Public Security's announcement, and is not folded into this document as the same law.
Cross border transfer
What it requires →
Article 20 enumerates the cases in which cross-border transfer of personal data is permitted; its substantive conditions, including any adequacy standard, government approval requirement, or data-localization element, were not read beyond the article's heading and opening clause this pass.
A separate penalties article confirms a materially strict enforcement posture: the maximum fine for an organization violating cross-border transfer regulations specifically is 5 percent of the organization's prior-year revenue, distinct from and higher than the Law's general violation fine tier.
Enforcement supervision
What it requires →
The Law names an agency in charge of personal data protection as the enforcement authority, without independently confirming the specific body's name this pass, though the Ministry of Public Security's role publicizing the Law's commencement suggests it sits under that ministry.
Administrative fines confirmed directly reach up to 5 percent of the prior year's organizational revenue for cross-border transfer violations specifically, with a separate, lower general fine tier referenced elsewhere in the same penalties article and not read in full.
A data-subject-rights clause confirms individuals may request the provision and deletion of their personal data, restriction of processing, and may object to processing, and separately may file complaints and denunciations, initiate lawsuits, and request compensation for damage in accordance with law, arming a private plaintiff.