Legal Alert

Vietnam’s New Personal Data Protection Law: Key Takeaways

Picture of May May Chan

May May Chan

Chief Executive Officer
of ZICO Insource

Picture of Tran Thi Minh Nguyet (Moon)

Tran Thi Minh Nguyet (Moon)

Legal Consultant
of ZICO Insource Vietnam

Legal Alert

Vietnam’s New Personal Data Protection Law: Key Takeaways

Picture of May May Chan

May May Chan

Chief Executive Officer

Picture of Tran Thi Minh Nguyet (Moon)

Tran Thi Minh Nguyet (Moon)

Legal Consultant
of ZICO Insource Vietnam

Vietnam’s Law on Personal Data Protection No. 91/2025/QH15 (“PDPL”), took effect on 1 January 2026. As the PDPL largely codifies the existing rules, businesses already compliant with Decree 13/2023 are unlikely to face significant changes. However, several new developments deserve attention.

1. Clearer rules on HR and recruitment data

The PDPL introduces specific requirements for handling personal data of the applicants and employees. In which, the company as the employers may only collect personal data necessary for recruitment and use it for recruitment purposes or other agreed purposes. Unless otherwise agreed, unsuccessful candidates’ personal data must be deleted or destroyed. Company wishing to retain candidate information for future opportunities should therefore obtain the applicant’s consent.

The law also requires employers to delete or destroy employees’ personal data after employment ends, unless retention is required by law or agreed with the employee. As Vietnamese law does not specify retention periods, employers should clearly document what data will be retained, for what purpose and for how long.

2. Ongoing compliance with data transfer assessments

The existing requirements to prepare Data Protection Impact Assessments (DPIAs) and Cross-Border Data Transfer Impact Assessments (TIAs) remain largely unchanged. The PDPL introduces limited exemptions for certain cross-border transfers, such as storing employees’ personal data on cloud services or where individuals transfer their own personal data abroad.

A notable change is the requirement to keep assessment dossiers up to date. Company shall update them every six months when changes occur and immediately following events such as corporate restructuring, changes to data protection service providers or changes to registered business activities involving personal data processing.

3. Recognition of de-identified data

For the first time, the PDPL recognizes de-identified personal data. Once personal data has been de-identified so that individuals can no longer be identified, it falls outside the scope of the PDPL, similar to the concept of anonymous data under the EU General Data Protection Regulation (GDPR).

However, the law does not prescribe technical standards for de-identification. Organizations remain responsible for implementing appropriate safeguards during the de-identification process and should regularly assess the risk of re-identification as technology and available data continue to evolve.

Key Takeaway

The PDPL does not introduce a fundamentally new compliance regime, but it strengthens existing obligations and clarifies several important areas. Businesses should review their HR data practices, ensure procedures are in place for updating impact assessment dossiers, and reassess their approach to de-identification.

Disclaimer: This article does not constitute legal advice or substitute for professional advice. Should you need legal advice or professional advice, please contact a lawyer or a professional for the advice that you are seeking.