← All guides
Privacy Law14 min read28 July 2026

Vietnam PDPD: Consent Architecture, Data Subject Rights, Cross-Border Transfers & MPS Enforcement (2026)

Complete guide to Vietnam's Personal Data Protection Decree 13/2023/ND-CP — covering consent, 72-hour data subject rights response, MPS A05 cross-border transfer registration, DPIA, DPO, breach notification, and criminal penalties.

Vietnam PDPD: Decree 13/2023/ND-CP — Vietnam's First Comprehensive Data Protection Regulation

Vietnam's Personal Data Protection Decree (Nghị định số 13/2023/NĐ-CP, or "PDPD") entered into force on July 1, 2023, establishing Vietnam's first dedicated personal data protection framework. With approximately 100 million people, Vietnam is Southeast Asia's third-largest population and one of its fastest-growing digital economies — with a government target of the digital economy reaching 20% of GDP by 2025. Decree 13 applies to any organisation or individual processing personal data of Vietnamese residents, regardless of where the processor is located, making extraterritorial reach a critical compliance consideration for SaaS companies, e-commerce platforms, and multinationals with Vietnamese users or customers.

Regulatory Framework and Enforcement Authority

Decree 13/2023/ND-CP was promulgated by the Vietnamese Government on April 17, 2023, and took effect on July 1, 2023. It replaces earlier fragmented provisions across multiple sector-specific decrees and aligns Vietnam's approach more closely with GDPR — though with important differences in consent requirements, response timelines, and cross-border transfer controls. The primary enforcement authority is the Ministry of Public Security (Bộ Công an), specifically Department A05 (Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao — Department of Cybersecurity and High-Tech Crime Prevention). A05 handles registrations, DPIAs, cross-border transfer assessments, breach notifications, and investigations. Sector-specific overlaps apply: the State Bank of Vietnam (SBV) for banking/fintech, Ministry of Health (MOH) for health data, Ministry of Information and Communications (MIC) for digital services, and Ministry of Industry and Trade (MOIT) for e-commerce.

Criminal sanctions under the Vietnam Penal Code 2015 (amended 2017) apply for intentional violations — Articles 288–294 cover illegal collection, disclosure, and use of personal data, with fines up to VND 200 million (approx. USD 8,000) and imprisonment of 3–7 years for serious or organised cases. Administrative fines under related penalty decrees apply per violation. Unlike GDPR's revenue-based penalties, Vietnam's fines are per-incident but criminal exposure for intentional misuse is significant and increasingly enforced by A05.

Scope and Key Definitions

Decree 13 covers the processing of dữ liệu cá nhân (personal data) — defined as any information relating to a specific individual that has been identified or can be identified, directly or indirectly. The decree distinguishes between:

  • Basic personal data (dữ liệu cá nhân cơ bản): Identification information (CCCD/CMND — national ID card, passport, tax code), name, date of birth, address, IP addresses, cookie data, location data, employment data, and similar information
  • Sensitive personal data (dữ liệu cá nhân nhạy cảm): 10 categories that attract enhanced obligations — political views, religious or philosophical beliefs, health information (including HIV/AIDS status), genetic data, biometric data used for identification, sexual life or sexual orientation, financial data and credit history, personal data of children under 16, and location data where processing reveals patterns about the data subject

Extraterritorial scope applies: Decree 13 covers processing by any entity inside or outside Vietnam where the data subjects are Vietnamese residents or where the processing activities relate to goods or services offered to people in Vietnam — mirroring GDPR's Art. 3(2) approach.

Lawful Basis and Consent Architecture

Decree 13 takes a consent-first approach. Article 11 specifies seven conditions for valid consent (sự đồng ý): (1) voluntary — not coerced or pressured; (2) informed — data subjects understand what they are consenting to; (3) specific — consent given for a clearly defined purpose; (4) unambiguous — affirmative action required, no implied or pre-ticked boxes; (5) expressed before processing begins; (6) can be verified — records maintained; (7) as easy to withdraw as to give. Separate explicit consent is required for each category of sensitive personal data — bundling consent for multiple sensitive categories in a single checkbox is non-compliant. Controllers must maintain evidence of consent: timestamp, method, scope, and withdrawal history.

Consent is not the only lawful basis. Article 17 of Decree 13 permits processing on other grounds: (a) contractual necessity, (b) legal obligation, (c) vital interests of the data subject, (d) legitimate interests (though guidance on this is less developed than GDPR). However, for sensitive personal data, consent remains the primary and safest basis — other bases for sensitive data require specific legal authorisation.

Consent withdrawal (rút lại sự đồng ý): data subjects have the right to withdraw consent at any time. Controllers must process withdrawal requests within 72 hours and must not penalise or disadvantage data subjects for withdrawing. If withdrawal means a service cannot be provided, the controller must clearly communicate this — but cannot make consent a condition of receiving non-essential services.

Data Subject Rights — 72-Hour Response Requirement

Vietnam's Decree 13 introduces a uniquely tight 72-hour response deadline for most data subject rights requests — significantly faster than GDPR's one-month standard. Article 9 establishes six key rights:

  • Right to access (Quyền tiếp cận): Request categories, purposes, recipients, and retention period of personal data — response within 72 hours
  • Right to correction (Quyền chỉnh sửa): Correct inaccurate or outdated data — 72 hours; third-party notification required where data has been shared
  • Right to deletion (Quyền xoá): Erase data when purpose is complete, consent is withdrawn, or processing is unlawful — 72 hours
  • Right to restriction (Quyền hạn chế): Suspend processing pending accuracy challenge or objection resolution
  • Right to data portability (Quyền di chuyển): Receive personal data in machine-readable format for transfer — 72 hours
  • Right to objection (Quyền phản đối): Object to processing, particularly direct marketing and profiling; controller must cease or provide compelling legitimate grounds

Controllers must maintain a free, accessible intake channel for rights requests, track requests against the 72-hour SLA, and publish the pathway to escalate complaints to MPS A05. The 72-hour window applies even for complex requests — organisations accustomed to 30-day GDPR responses will need to substantially accelerate their processes.

Privacy Notice Requirements

Article 13 of Decree 13 requires a privacy notice (thông báo xử lý dữ liệu cá nhân) to be provided before or at the point of personal data collection. Required elements include: identity and contact details of the controller; DPO contact (if appointed); purposes of processing; legal basis; categories of recipients; retention period; data subject rights and how to exercise them; information about cross-border transfers (if applicable); and complaint mechanism. The notice must be available in Vietnamese (or with an accessible Vietnamese translation) and must be updated whenever processing changes materially. For consumer-facing applications, the notice should be prominently accessible — typically from the homepage or at the point of data collection (registration/checkout/contact form).

Cross-Border Transfer Controls — MPS A05 Registration

Article 25 of Decree 13 imposes one of the most significant obligations for multinationals and cloud-service providers: cross-border transfers of Vietnamese personal data require a pre-transfer impact assessment submitted to MPS Department A05. This applies to systematic or large-scale cross-border transfers — and specifically to transfers of sensitive personal data. The impact assessment (đánh giá tác động chuyển dữ liệu cá nhân ra nước ngoài) must document: controller and recipient identities; destination countries; categories of data transferred; transfer volume; purposes; protection measures implemented; and a risk assessment. Assessments must be registered on the MPS online portal and updated when transfers change.

This differs significantly from GDPR's model (which relies on adequacy decisions and standard contractual clauses without prior regulatory notification for most transfers) and from Singapore's PDPA (which uses contractual protections without notification). Controllers transferring Vietnamese data to cloud providers, analytics tools, CRM platforms, or offshore teams must complete this assessment before the transfer begins — retroactive compliance for existing transfers is a priority action for most organisations. The receiving country must provide equivalent protection to Decree 13, or binding contractual safeguards (contractual clauses or BCRs) must be in place.

Data localisation under the Vietnam Cybersecurity Law 2018 (Luật An ninh mạng, Art. 26) imposes additional requirements for critical information infrastructure (CII) operators and entities providing services in Vietnam that collect, exploit, analyse, or process data about Vietnamese users, relationships, and activities. These operators must store Vietnamese user data locally for a minimum period and may be required to establish a representative office in Vietnam. The Ministry of Public Security and Ministry of Information and Communications jointly administer these requirements — entities in financial services, healthcare, telecommunications, and large e-commerce platforms are most commonly affected.

Data Protection Impact Assessment (DPIA)

Article 24 of Decree 13 requires a Data Protection Impact Assessment (đánh giá tác động xử lý dữ liệu cá nhân) for high-risk processing activities. Triggers include: large-scale profiling of Vietnamese data subjects; systematic surveillance; processing of sensitive personal data at scale; deployment of new technologies that could create high risks; and automated decision-making that significantly affects data subjects. The DPIA must document the purpose and necessity of processing, proportionality assessment, identified risks, and safeguards implemented. Completed DPIAs must be submitted to MPS A05 and updated when the high-risk processing changes materially.

Data Protection Officer (DPO)

Article 28 of Decree 13 requires the appointment of a Data Protection Officer (cán bộ bảo vệ dữ liệu cá nhân) for organisations that: process sensitive personal data at scale; conduct systematic surveillance of Vietnamese data subjects; perform large-scale cross-border transfers; or are critical information infrastructure operators. The DPO must have data protection expertise, operate with independence, have adequate resources, and have direct access to senior management. The DPO's identity and contact details must be published (typically in the privacy notice and on the website), and MPS A05 must be notified of the DPO appointment and any changes.

Security Measures and Breach Notification

Article 26 requires technical and organisational security measures appropriate to the risk of the processing — including encryption, access controls, authentication, network security, and physical safeguards. Annual security reviews and periodic penetration testing are expected for organisations handling sensitive personal data.

Breach notification (Articles 23–27): controllers must notify MPS A05 within 72 hours of becoming aware of a personal data breach (tương tự GDPR's 72-hour window). The notification must include: breach description; categories and approximate number of affected data subjects; categories of data affected; likely consequences; remediation steps taken. Individual data subject notification is required for breaches likely to cause harm to the affected individuals — without undue delay. All breaches (including non-notifiable ones) must be logged in an incident register retained for MPS inspection. Processors must notify controllers immediately upon discovering a breach.

Processor Contracts and Accountability

Article 30 requires written contracts with all personal data processors (Bên Xử Lý). These contracts must include: binding processing instructions; security obligations equivalent to the controller's own obligations; restrictions on sub-processor engagement without controller approval; immediate breach notification obligations; deletion or return of data on termination; and audit rights reserved to the controller. Organisations relying on cloud providers (AWS, Google Cloud, Azure, local providers) or SaaS tools that process Vietnamese personal data must ensure these contracts are in place — and that those providers have agreed to the cross-border transfer assessment if data moves outside Vietnam.

Building a Vietnam PDPD Compliance Programme

A pragmatic 90-day roadmap:

  • Days 0–30 (Critical): Appoint DPO and notify MPS A05 if required; complete cross-border transfer inventory and register pending assessments with MPS A05 portal; update privacy notices for all Art. 13 elements in Vietnamese; implement consent management for sensitive data categories; establish 72-hour data subject rights SLA; implement breach notification procedure; review CII/data localisation status under Cybersecurity Law 2018
  • Days 31–60 (High Priority): Complete DPIAs for high-risk processing and submit to A05; execute processor contracts with all Bên Xử Lý; implement records of processing activities; data retention schedule with automated deletion; staff training; security measures documentation
  • Days 61–90 (Governance): Complete Vietnam PDPD compliance programme documentation; integrate A05 registration and DPIA submission into change management; map sector-specific overlays (SBV/MOH/MIC); privacy by design embedded in development lifecycle

Organisations with existing GDPR programmes can leverage those as a foundation — the consent architecture, DPIA, DPO, and data subject rights processes are broadly transferable. Key differences to account for: 72-hour rights response (vs GDPR 1 month), pre-transfer MPS A05 registration (vs GDPR SCCs/adequacy only), separate explicit consent per sensitive data category, and criminal liability exposure for intentional violations.

Use the Vietnam PDPD Compliance Checker

ComplyKit's Vietnam PDPD Compliance Checker covers 42 key obligations across six categories: Lawful Basis & Consent, Data Subject Rights, Controller Obligations & Privacy Notice, Security & Breach Notification, Cross-Border Transfers, and DPO/Governance & MPS Enforcement. Free, no account required. Generates an AI-drafted HTML compliance report with gap analysis, 90-day roadmap, and Decree 13/2023 Article references.