Asia-Pacific Vietnam

Vietnam Decree 13 Compliance: PDPD Rules and the 2026 PDP Law

Vietnam's Decree 13/2023 on personal data protection: consent-first processing, impact dossiers, cross-border filings, MPS supervision, and the PDP Law arriving 2026.

Regulation

Decree 13/2023/ND-CP (effective 1 July 2023); Law on Personal Data Protection (effective 1 January 2026)

Max Penalty

Under the 2025 PDP Law: fines up to 5% of prior-year revenue for violations such as unlawful cross-border transfer; data-selling penalties up to 10x the illicit gain

Enforcing Authority

Ministry of Public Security (MPS), Department of Cybersecurity (A05)

Official Source

english.mst.gov.vn

Executive Summary

  • Decree 13/2023/ND-CP (the PDPD), effective 1 July 2023, is Vietnam's first consolidated data protection instrument, applying to Vietnamese and foreign entities processing personal data of individuals in Vietnam.
  • It is consent-first: processing requires explicit, affirmative consent absent narrow exceptions (emergencies, law, state functions, contract obligations), with no legitimate-interests basis, closer to China's PIPL than to GDPR.
  • Two filing regimes distinguish Vietnam: a processing impact assessment dossier and, for offshore transfers, a transfer impact dossier, each filed with the MPS's A05 within 60 days of processing/transfer commencement.
  • Data subjects hold broad rights (know, consent, access, withdraw, delete, restrict, object, complain, claim damages), and marketing use requires distinct consent.
  • A full Law on Personal Data Protection was enacted in June 2025 and takes effect 1 January 2026, adding revenue-based fines (to 5% for unlawful transfers) and hard bans on buying and selling personal data.

Vietnam built its privacy regime the way it builds internet regulation generally: through the security ministry. Decree 13 is administered not by a data protection authority but by the Ministry of Public Security’s cybersecurity department (A05), it demands standing filings rather than internal accountability records, and it treats consent as nearly the only lawful ground. For global programs, Vietnam is the jurisdiction where GDPR instincts mislead most: there is no legitimate interests to fall back on, and your processing and transfer inventories are not internal documents but dossiers sitting in a ministry’s registry.

InstrumentsDecree 13/2023/ND-CP (1 July 2023); PDP Law (1 January 2026)
SupervisorMPS / A05
Signature dutiesConsent-first processing; 60-day impact and transfer dossiers
2026 penaltiesUp to 5% of revenue (transfers); 10x gains (data trading)
Government portalMIC (English)

Building Vietnam compliance

Consent architecture. Explicit, per-purpose, affirmative consent with proof of capture; separate consent for marketing and for sensitive-data processing, plus the required notification that sensitive data is involved. Withdrawal must be honored and cascaded to third parties. Pre-ticked boxes and bundled terms fail the decree’s express standards.

The two dossiers. Treat them as living registrations: an impact dossier covering all processing (file within 60 days of starting, update on changes) and a transfer dossier per cross-border arrangement. Contents parallel a GDPR ROPA-plus-DPIA, purposes, categories, recipients, safeguards, retention, but the audience is A05, which inspects, comments, and can suspend transfers. Multinationals commonly route filings through their Vietnamese entity or a local representative.

Rights and incidents. Data subjects can access, correct, delete, restrict, object, and withdraw; the decree expects response within 72 hours for several obligations, and personal data violations must be notified to A05 within 72 hours of occurrence. Damages claims and complaints run through general civil law.

2026 readiness. The PDP Law converts today’s soft-sanction environment (administrative decrees with modest fixed fines) into revenue-scaled liability. If your Vietnam posture has been filing-light, close the gap before January 2026: the dossier registry gives A05 a ready-made enforcement queue.

Vietnam’s consent absolutism and security-ministry supervision place it nearest to China’s PIPL in the regional spectrum, far from Singapore’s exception-rich PDPA. Map what your Vietnam-facing properties collect and transmit with a free scan.

Frequently Asked Questions

Who must comply with Decree 13?

Every agency, organization, and individual processing personal data in Vietnam, plus foreign entities directly processing data of individuals located in Vietnam. There are no turnover or volume thresholds. Both 'basic' personal data and 'sensitive' personal data (health, biometrics, finance, location, criminal data, and more) are covered, with sensitive processing requiring notification to the data subject that such data is being processed.

Is consent really required for almost everything?

Largely yes. Consent must be explicit, affirmative (silence is not consent), purpose-specific, and given per data type; the decree's exceptions are narrow: life-and-health emergencies, statutory obligations, state security and disclosure required by law, and processing to perform contractual obligations. There is no balancing-test basis, so analytics, enrichment, and most marketing run on consent, obtained separately for each purpose bundle.

What is the impact dossier requirement?

Controllers and processors must prepare a personal data processing impact assessment dossier (processing purposes, data types, recipients, safeguards, transfer details) and file it with the MPS Department of Cybersecurity (A05) within 60 days of commencing processing, keeping it updated. It is a standing filing, not a one-off, and A05 can inspect and demand corrections.

How do cross-border transfers work?

Transfers of Vietnamese citizens' data abroad require a separate transfer impact assessment dossier filed with A05 within 60 days of the transfer commencing, plus notification to A05 with transfer contact details after successful transfer. The MPS can order transfer suspension for violations, including where transferred data is misused or breaches Vietnamese law. The 2026 PDP Law keeps the dossier architecture and attaches fines up to 5% of revenue for unlawful transfers.

What changes under the 2026 PDP Law?

The law (passed June 2025, effective 1 January 2026) carries the decree's framework into statute and hardens sanctions: administrative fines scaled to revenue (up to 5% of prior-year revenue for cross-border violations; data-trading penalties up to 10x illicit gains), explicit prohibition of buying and selling personal data, DPO expectations, and phased compliance for SMEs. Existing Decree 13 dossiers and consent architecture carry forward as the baseline.

Regulatory Crosswalk

GDPRVietnam PDPDPIPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.