This guide provides businesses with a practical overview of Vietnam’s new Law on Personal Data Protection (LPDP), effective from 1 January 2026. It explains who must comply, how personal data is classified, key consent requirements, DPO obligations, impact assessment reports, cross-border data transfer rules, and potential penalties for non-compliance.
What can you expect from this guide?
Vietnam’s personal data protection landscape is entering a new phase with the introduction of the Law on Personal Data Protection (LPDP), replacing the previous Decree 13 framework. For businesses collecting, storing, or processing personal data from Vietnamese customers, employees, or users, understanding these new requirements is essential.
This guide breaks down the key obligations under the LPDP in a clear and practical way, helping businesses identify whether they fall within the law’s scope, determine their role as a data controller or processor, manage consent properly, prepare required impact assessments, and strengthen internal compliance procedures. It also highlights higher penalties and the law’s extraterritorial reach, making it a useful resource for both local and foreign companies operating in or serving Vietnam.
This guide will cover these key points:
- Who must comply with Vietnam’s LPDP
- Data controller, processor, and third-party responsibilities
- Basic vs. sensitive personal data classification
- Consent requirements and lawful processing exceptions
- Data Protection Officer requirements
- DPIA and outbound transfer impact assessment obligations
- Prohibited acts and potential penalties for violations