What Is Law No. 91/2025/QH15 on Personal Data Protection?
Law No. 91/2025/QH15 on Personal Data Protection was adopted by the National Assembly on 26 June 2025 and became effective 1 January 2026 — a major currentness development, since Viet Nam's data-protection regime had previously rested only on a government decree, not a full statute. Its implementing Decree No. 356/2025/ND-CP, also effective 1 January 2026, expressly provides that the prior Decree No. 13/2023/ND-CP expires on Decree 356's effective date, so Decree 13 is no longer the operative general personal-data instrument. The current core framework is Law 91 plus Decree 356 plus a new sanctions instrument, Decree No. 330/2026/ND-CP on administrative penalties for cybersecurity and personal-data violations, effective 19 August 2026. A separate, concurrently changing layer affects data localization: Cybersecurity Law No. 116/2025/QH15, effective 1 July 2026, requires covered domestic and foreign online-service providers operating in Vietnam to store personal-information, user-relationship, and user-created data within Vietnam, with a Vietnam branch or representative-office requirement for covered foreign enterprises. Its implementing Decree No. 333/2026/ND-CP is also in force, though its interaction with the prior localization decree (Decree 53/2022/ND-CP) remains an open transition question.
At a glance
- Full name
- Law No. 91/2025/QH15 on Personal Data Protection
- Short code
- Law No. 91/2025
- Jurisdiction
- Viet Nam
- Enacted
- 2025
- Last major update
- Effective 1 January 2026, superseding the prior Decree No. 13/2023/ND-CP; implementing Decree No. 356/2025/ND-CP and sanctions Decree No. 330/2026/ND-CP (effective 19 August 2026) both in force
- Regulator
- Ministry of Public Security (MPS) — Department of Cybersecurity and High-Tech Crime Prevention (A05)
- Private right of action
- Yes
- Statutory citation
- Law No. 91/2025/QH15 on Personal Data Protection
Scope, who Law No. 91/2025 covers
Protected data
Data subject rights
To know about the processing of personal data
To consent, refuse, or withdraw consent
To view, edit, or request correction of personal data
To request provision, deletion, or restriction of processing, and to object
To complain, denounce, sue, and request compensation
To request protective measures from competent authorities, organizations, or persons
Notable features
Viet Nam has an unusually high rate of near-simultaneous instrument changes clustered in late 2025/2026: Law 91 (1 January 2026), Decree 356 (1 January 2026), Decree 330 (19 August 2026), Cybersecurity Law 116 (1 July 2026), and Decree 333 (19 August 2026) all took or take effect within roughly eight months of each other. Any description of the framework must be dated precisely — a pre-2026 summary describing only Decree 13/2023 is stale, since Decree 356 expressly provides that Decree 13 has expired.
Enforcement & penalties
Regulator: Ministry of Public Security (MPS) — Department of Cybersecurity and High-Tech Crime Prevention (A05)
Penalties: Law 91 Article 8 administrative-fine maximums: personal-data purchase or sale — 10x the violation proceeds, subject to a VND 3 billion fallback; cross-border-transfer violations — 5% of prior-year revenue, subject to a VND 3 billion fallback; other personal-data violations — VND 3 billion flat; individuals are capped at half the organizational maximum in each category. Decree 330's detailed offense-specific penalty schedule has not been independently verified from its full text (an access limitation, not a finding that the schedule is absent).
Private right of action: Article 4(1) grants a right to complain, denounce, sue, and request compensation, but no dedicated personal-data complaint-adjudication procedure or PDP-specific adjudication deadline has been located in Law 91 or Decree 356 — the statutory deadlines that do exist govern controllers'/processors' handling of individual rights requests (2 working days response, 10-20 day implementation depending on request type) and a separate 72-hour breach-notification duty, not the resolution of a formal complaint.
Relevance to data brokers
No Vietnam-specific data-broker complaint route, broker takedown mechanism, or public-record-specific deletion procedure has been located in official sources searched. The general framework prohibits personal-data purchase or sale except where legally permitted, limits public disclosure to a specific purpose and proportionate scope, and provides general access, correction, restriction, objection, and deletion rights under Law 91 Articles 7 and 14-16.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Decree 13/2023 still Vietnam's personal-data law?+
No. Decree 13/2023/ND-CP was superseded when Law No. 91/2025/QH15 and its implementing Decree No. 356/2025/ND-CP took effect on 1 January 2026 — Decree 356 expressly provides that Decree 13 expires on that date. Any source describing only Decree 13 is outdated.
Does Vietnam require personal data to be stored locally?+
Law 91 itself is not a blanket in-Vietnam-storage mandate — it uses cross-border transfer impact assessments and stop-transfer powers instead. But a separate law, Cybersecurity Law No. 116/2025/QH15, effective 1 July 2026, does require covered domestic and foreign online-service providers to store personal-information, user-relationship, and user-created data within Vietnam.
Who enforces Vietnam's personal-data law?+
The Ministry of Public Security is the lead State-management body (except matters under the Ministry of National Defense), acting through a specialized unit identified in MPS's own procedure notice as the Department of Cybersecurity and High-Tech Crime Prevention (A05), with the National Personal Data Protection Portal as the petition-intake channel.
Official sources & citations
Other international privacy regimes
Law No. 91/2025 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
