Country:越南 · Data Privacy
Medium confidenceUpdated 2026-07-15Handbook

Vietnam · Data Privacy

Vietnam's Personal Data Protection Decree (PDPD, effective 2023) governs personal-data processing, sets strict cross-border transfer conditions, and shows a 'important data' localisation tendency. It requires a dual assessment with China's PIPL.

Key points

Procedure

  1. Data inventory and classification (general/sensitive).
  2. Privacy policy and consent mechanism.
  3. Cross-border: DPIA + standard contract + A05 filing.
  4. Data-subject rights response mechanism.
  5. Designate a data-protection contact.

Hard requirements

Costs

Compliance build; filing cost.⏱ ⏱ Timeline:Compliance framework before launch.

⚠ Common risks

  • Unfiled cross-border transfer → penalty and suspended transfer.
  • Important-data localisation细则 refined → non-compliance.
  • Conflict with PIPL (see data topic).
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese-invested entities operating in Vietnam, processing Vietnam personal data (wherever the processor is located), or transferring Vietnam personal data back to China (governed by the PDPD and the 2025 Personal Data Protection Law).

Prerequisites

  • Clarify data categories processed in Vietnam (general/sensitive).
  • Determine controller/processor role.
  • Reserve impact-assessment and A05 filing budget.
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data inventory and classification
Inventory personal data; distinguish general vs sensitive; build a processing record.
Legal / IT2–3 weeksInternalData inventory, classification tableSensitive data needs explicit consent
Penalty:Mis-classification加重 liability
2Privacy policy and consent mechanism
Publish a Vietnamese privacy policy; obtain processing consent (explicit for sensitive data).
Legal1–2 weeksInternalPrivacy policy, consent recordVerifiable and traceable
Penalty:Administrative penalty and suspension
3Data Processing Impact Assessment (DPIA)
Complete the DPIA per PDPD Article 9 and submit via the A05 national portal (https://baovedlcn.gov.vn).
Legal / compliance2–4 weeksInternal / lawyerDPIA report, A05 portal submissionAnnual public-security credit rating
Penalty:No assessment / no submission → penalty
4Cross-border transfer: DPIA + standard contract + A05 filing
Before cross-border transfer, complete the Cross-Border Transfer Impact Assessment (CB-TIA), sign standard contractual clauses, and file/obtain approval with A05 (Ministry of Public Security).
Legal3–6 weeksFiling / lawyerCB-TIA, standard contract, A05 filing receiptTransfer back to China must also link PIPL export mechanism
Penalty:Unfiled transfer may be suspended and penalised
5Data-subject rights response
Build access, correction, deletion and consent-withdrawal response flows.
DPO / supportOngoingInternalDSAR processWritten record required
Penalty:Refusing response → penalty
6Designate data-protection contact
Appoint a reachable data-protection officer/contact liaising with A05.
ManagementOngoingLabourContact appointment & publicationRecommend an operational function
Penalty:Regulatory liaison gap
7Ongoing compliance and annual assessment
Cooperate with A05 annual credit rating; conduct periodic review and training.
ComplianceAnnualInternalAnnual assessment & trainingImportant data shows localisation tendency
Penalty:Persistent violation → accumulated penalties

✅ Self-check list

⚠ Common pitfalls

Cross-border transfer without A05 filing影响:Ordered to suspend transfer and penalised.规避:Complete CB-TIA, sign contract and file first.
Ignoring the 2025 Personal Data Protection Law upgrade影响:Compliance basis失效.规避:Update policies per the new law.
Ignoring PIPL export for China-bound transfer影响:Dual violation.规避:Handle China-side export mechanism in parallel.
Sensitive data with only implied consent影响:Consent invalid.规避:Obtain explicit consent.
No A05 annual credit-rating preparation影响:Rating hurts operations.规避:Standardise and retain evidence early.
Misjudging localisation as gov-only data影响:Important-data violation.规避:Watch sector rule rollout.

📅 Ongoing post-incorporation obligations

  • Cooperate with A05 annual credit rating.
  • Maintain cross-border transfer filing validity.
  • Sustain data-subject rights response.
  • Periodic staff training and policy review.
  • Keep China-bound PIPL export mechanism valid.

🔗 Official portals

📎 Source:https://www.mic.gov.vn ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.