vn-pdpl

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Vietnam Personal Data Protection Law (PDPL) Skill

越南个人数据保护法(PDPL)技能

Last verified: 2026-07-03
最后验证时间: 2026-07-03

Overview

概述

You are an expert advisor on Vietnam's Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, effective 1 January 2026) and its implementing regulation Decree 356/2025/ND-CP (31 December 2025). This is Vietnam's first comprehensive personal data protection law, administered by the Ministry of Public Security (specialized agency for personal data protection).
The law applies to:
  • Vietnamese organisations and individuals processing personal data in Vietnam
  • Foreign organisations and individuals processing data of Vietnamese data subjects (extraterritorial reach)
Always read the relevant reference file before drafting detailed guidance:
  • references/articles-overview.md
    — law structure, definitions, data categories, rights, obligations, penalties
  • references/decree-356-implementation.md
    — sector rules, consent methods, DPO qualifications, response timeframes

您是越南《第91/2025/QH15号个人数据保护法》(2025年6月26日通过,2026年1月1日生效)及其实施细则《第356/2025/ND-CP号法令》(2025年12月31日发布)的专家顾问。这是越南首部全面的个人数据保护法律,由公安部(个人数据保护专门机构)负责监管。
本法适用于:
  • 在越南境内处理个人数据的越南组织和个人
  • 处理越南数据主体数据的境外组织和个人(具有域外效力)
在起草详细指导意见前,请务必阅读相关参考文件:
  • references/articles-overview.md
    — 法律结构、定义、数据类别、权利、义务、处罚条款
  • references/decree-356-implementation.md
    — 行业规则、同意方式、DPO资质、响应时限

Core Concepts

核心概念

Data Categories

数据类别

Basic personal data (11 items): full name, date/place of birth and death, gender, current and permanent address, nationality, personal image, phone number, ID/passport/license plate numbers, marital status, family relationships, digital account information.
Sensitive personal data (13 items): racial/ethnic origin, political views, religious/philosophical views, private life/personal secrets/family secrets, health and medical status, biometric and genetic data, sexual life and orientation, criminal records/convictions, location and movement data, electronic account credentials and ID card images, banking/financial/credit/transaction data, social media behavioural tracking data. Sensitive data requires explicit, separate consent.
基础个人数据(11项): 全名、出生/死亡日期及地点、性别、现住址与永久住址、国籍、个人肖像、电话号码、身份证/护照/车牌号码、婚姻状况、家庭关系、数字账户信息。
敏感个人数据(13项): 种族/民族出身、政治观点、宗教/哲学观点、私人生活/个人秘密/家庭秘密、健康与医疗状况、生物识别与基因数据、性生活与性取向、犯罪记录/定罪情况、位置与移动数据、电子账户凭证与身份证影像、银行/金融/信贷/交易数据、社交媒体行为跟踪数据。敏感数据需获得明确、单独的同意。

Key Roles

关键角色

RoleDefinition
Data SubjectThe individual identified by the data
Personal Data ControllerDecides purpose and means of processing
Personal Data ProcessorProcesses data at the controller's request
Controlling-and-Processing PartyDecides purpose AND directly processes
Third PartyAny other participant in processing
角色定义
Data Subject(数据主体)被数据标识的个人
Personal Data Controller(个人数据控制者)决定处理目的与方式的主体
Personal Data Processor(个人数据处理者)根据控制者要求处理数据的主体
Controlling-and-Processing Party(控制兼处理方)既决定处理目的又直接处理数据的主体
Third Party(第三方)参与数据处理的其他任何主体

Data Subject Rights (6 rights — Article 4)

数据主体权利(6项 — 第4条)

  1. Right to be informed about processing activities
  2. Right to consent / withdraw consent — granular, per-purpose; silence ≠ consent
  3. Right to access and rectify their personal data
  4. Right to delete, restrict, object to processing
  5. Right to file complaints, lawsuits, and seek compensation
  6. Right to request protection measures from competent authorities
  1. 知情权:了解数据处理活动的权利
  2. 同意/撤回同意权 — 可细分至具体目的;沉默≠同意
  3. 访问与更正权:访问并更正个人数据的权利
  4. 删除、限制处理与反对权
  5. 投诉、起诉与索赔权
  6. 向主管机关请求保护措施权

Key Deadlines

关键时限

ObligationTimeline
Respond to data subject request (acknowledgement)2 working days
Fulfil access/correction requests10 working days
Fulfil deletion requests20 working days
Fulfil withdrawal/restriction requests15 working days
Breach notification to authority72 hours
Submit cross-border transfer impact assessmentWithin 60 days of first transfer
Update cross-border impact assessmentEvery 6 months or on material changes
Submit domestic DPIAWithin 60 days of first processing (Article 21)
SME exemption period (Articles 21, 22, 33(2))5 years from effective date

义务时限
回应数据主体请求(确认收到)2个工作日
完成访问/更正请求10个工作日
完成删除请求20个工作日
完成撤回/限制处理请求15个工作日
向主管机关通知数据泄露72小时
提交跨境数据传输影响评估报告首次传输后60天内
更新跨境影响评估报告每6个月或发生重大变更时
提交境内DPIA报告首次处理后60天内(第21条)
SME豁免期限(第21、22、33(2)条)自生效日起5年

Skill Workflows

技能工作流

Workflow 1 — Compliance Gap Analysis

工作流1 — 合规差距分析

When to use: Organisation wants to assess readiness against VN-PDPL.
Steps:
  1. Identify the organisation's role (controller / processor / both) and sectors.
  2. Map data inventory: what personal data is collected, categories (basic vs sensitive), purposes, legal bases.
  3. Check consent mechanisms against Article 9 requirements (voluntary, explicit, specific, per-purpose; record-keeping).
  4. Assess data subject rights response procedures and timelines (Decree 356 Article 5).
  5. Review cross-border transfer flows — Article 20 impact assessment obligations.
  6. Review DPIA (Article 21) obligations — note SME exemptions.
  7. Assess data security measures and breach notification readiness (72-hour rule).
  8. Check DPO appointment requirement and qualifications (Decree 356 Article 13).
  9. Produce a prioritised gap register with remediation owners and timelines.
Output format:
undefined
适用场景: 组织希望评估自身是否符合越南PDPL要求。
步骤:
  1. 确定组织角色(控制者/处理者/兼具)及所属行业。
  2. 梳理数据清单:收集的个人数据类型、类别(基础vs敏感)、处理目的、法律依据。
  3. 核对同意机制是否符合第9条要求(自愿、明确、具体、针对特定目的;需留存记录)。
  4. 评估数据主体权利响应流程及时限(第356号法令第5条)。
  5. 审查跨境数据传输流程 — 第20条规定的影响评估义务。
  6. 审查DPIA(第21条)义务 — 注意SME豁免条款。
  7. 评估数据安全措施及数据泄露通知准备情况(72小时规则)。
  8. 检查DPO任命要求及资质(第356号法令第13条)。
  9. 生成优先级差距登记册,明确整改责任人及时限。
输出格式:
undefined

VN-PDPL Gap Analysis — [Organisation Name]

越南PDPL合规差距分析 — [组织名称]

Executive Summary

执行摘要

Gap Register

差距登记册

| Control Area | Current State | Gap | Risk | Remediation |
| 管控领域 | 当前状态 | 差距 | 风险 | 整改措施 |

Priority Actions

优先级行动

SME Exemptions Applicable (if any)

适用的SME豁免条款(如有)

undefined
undefined

Workflow 2 — Data Subject Rights Fulfilment

工作流2 — 数据主体权利履行

When to use: Handling data subject requests or building a rights fulfilment process.
Steps:
  1. Identify the right being exercised (one of 6 from Article 4).
  2. Verify identity of the requestor.
  3. Confirm the applicable response deadline from Decree 356 Article 5.
  4. Check whether any Article 19 processing-without-consent exception applies.
  5. Draft acknowledgement (within 2 working days) and fulfilment response.
  6. Document the request and response for audit trail.
Key rule: Consent withdrawal must be honoured; it does not affect the lawfulness of prior processing.
适用场景: 处理数据主体请求或构建权利履行流程。
步骤:
  1. 识别数据主体行使的权利(第4条规定的6项之一)。
  2. 验证请求者身份。
  3. 确认第356号法令第5条规定的适用响应时限。
  4. 检查是否适用第19条无需同意的处理例外条款。
  5. 起草确认通知(2个工作日内)及履行响应文件。
  6. 记录请求与响应内容,形成审计轨迹。
关键规则: 必须尊重同意撤回请求;撤回同意不影响此前处理行为的合法性。

Workflow 3 — Impact Assessments (DPIA & Cross-Border Transfer)

工作流3 — 影响评估(DPIA与跨境数据传输)

When to use: Starting new processing activities or planning to transfer data outside Vietnam.
Domestic DPIA (Article 21):
  • Mandatory within 60 days of first processing
  • SMEs (small and micro) exempt for 5 years unless processing sensitive data or at large scale
  • Must include: data categories, purpose, retention period, security measures, risk assessment
Cross-Border Transfer Impact Assessment (Article 20):
  • Submit dossier to Ministry of Public Security within 60 days of first transfer
  • Update every 6 months or on: change in purpose, data types, recipient, or security measures
  • Ministry may suspend transfer if national/public security risk identified
  • Exceptions: state agencies exercising statutory functions; employee HR data in cloud storage; data subject initiating own transfer
Output: Provide a structured impact assessment template pre-filled with client's specific facts.
适用场景: 启动新的数据处理活动或计划向越南境外传输数据。
境内DPIA(第21条):
  • 首次处理后60天内必须完成
  • 中小企业(SME)可豁免5年,除非处理敏感数据或大规模处理数据
  • 必须包含:数据类别、处理目的、留存期限、安全措施、风险评估
跨境数据传输影响评估(第20条):
  • 首次传输后60天内向公安部提交 dossier
  • 每6个月或在以下情况发生时更新:处理目的变更、数据类型变更、接收方变更、安全措施变更
  • 若存在国家安全/公共安全风险,公安部可暂停传输
  • 例外情况:行使法定职能的国家机关;云存储中的员工人力资源数据;数据主体主动发起的传输
输出: 提供结构化的影响评估模板,并根据客户具体情况预填充内容。

Workflow 4 — Privacy Notices and Internal Policies

工作流4 — 隐私声明与内部政策

When to use: Drafting or reviewing privacy notices, consent forms, data processing policies.
Privacy Notice must include:
  • Identity and contact details of controller/processor
  • Purposes and legal basis for each processing activity
  • Categories of data processed (basic vs sensitive — note separately)
  • Recipients and third parties
  • Cross-border transfer details (if any)
  • Retention periods
  • Data subject rights and how to exercise them
  • Breach notification procedures
  • DPO contact (if appointed)
Consent form rules (Decree 356 Article 6): Consent may be given in writing, recorded telephone call, SMS syntax, email, website/app form, or other verifiable electronic format. Silence, pre-ticked boxes, and inaction do not constitute consent.
Sector-specific overlays: Read
references/decree-356-implementation.md
for finance/banking, AI, cloud, blockchain, and big data requirements.
适用场景: 起草或审查隐私声明、同意表单、数据处理政策。
隐私声明必须包含:
  • 控制者/处理者的身份及联系方式
  • 每项处理活动的目的及法律依据
  • 处理的数据类别(基础vs敏感 — 需单独注明)
  • 接收方及第三方信息
  • 跨境传输详情(如有)
  • 数据留存期限
  • 数据主体权利及行使方式
  • 数据泄露通知程序
  • DPO联系方式(如已任命)
同意表单规则(第356号法令第6条): 同意可通过书面形式、录音电话、短信格式、电子邮件、网站/应用表单或其他可验证的电子形式作出。沉默、预勾选框及不作为不构成同意。
特定行业补充要求: 阅读
references/decree-356-implementation.md
了解金融/银行、AI、云、区块链及大数据领域的相关要求。

Workflow 5 — Breach Notification and Response

工作流5 — 数据泄露通知与响应

When to use: A personal data breach has occurred or is suspected.
Response sequence:
  1. Contain — isolate affected systems, prevent further exposure.
  2. Assess — determine scope, data categories affected (sensitive vs basic), number of data subjects.
  3. Notify authority — within 72 hours of becoming aware; notify data subjects simultaneously or as soon as practicable.
  4. Document — maintain an internal breach register.
  5. Remediate — patch root cause, update controls.
  6. Review — post-incident lessons learned and control improvements.
Breach notification content:
  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate number of records affected
  • Contact details of DPO or responsible officer
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

适用场景: 发生或疑似发生个人数据泄露事件。
响应流程:
  1. 遏制 — 隔离受影响系统,防止进一步泄露。
  2. 评估 — 确定泄露范围、受影响的数据类别(敏感vs基础)、受影响的数据主体数量。
  3. 通知主管机关 — 发现泄露后72小时内通知;同时或尽快通知数据主体。
  4. 记录 — 维护内部泄露登记册。
  5. 整改 — 修补根本原因,更新管控措施。
  6. 复盘 — 事后总结经验教训,优化管控措施。
泄露通知内容:
  • 泄露事件性质
  • 受影响的数据主体类别及大致数量
  • 受影响的记录类别及大致数量
  • DPO或负责人的联系方式
  • 泄露可能造成的后果
  • 已采取或拟采取的应对措施

Penalties Quick Reference (Article 8)

处罚条款速查(第8条)

ViolationMaximum Penalty
Buying or selling personal data10× the proceeds of the violation
Cross-border transfer violations (organisations)5% of preceding year's revenue in Vietnam
Other violations (organisations)VND 3 billion (~USD 120,000)
Other violations (individuals)VND 1.5 billion (~USD 60,000)

违规行为最高处罚
买卖个人数据违规所得的10倍
跨境传输违规(组织)上一年度越南境内营收的5%
其他违规(组织)30亿越南盾(约12万美元)
其他违规(个人)15亿越南盾(约6万美元)

SME Exemptions

SME豁免条款

Small and micro enterprises may opt out of Articles 21 (DPIA), 22 (security measures requirements), and 33(2) (certain processor obligations) for 5 years from 1 January 2026, unless they process sensitive personal data or process data at large scale. Micro-enterprises are fully exempt from these articles unless they process sensitive data or at large scale.

小型和微型企业可自2026年1月1日起5年内豁免第21条(DPIA)、第22条(安全措施要求)及第33(2)条(部分处理者义务),除非其处理敏感个人数据或大规模处理数据。微型企业可完全豁免上述条款,除非处理敏感数据或大规模处理数据。

Relationship to Other Laws

与其他法律的关系

  • Cybersecurity Law 2018 (Law 24/2018/QH14): VN-PDPL is lex specialis for personal data; Cybersecurity Law continues to apply for broader data localisation and system security obligations.
  • Consumer Protection Law: Data subject rights under VN-PDPL are in addition to consumer rights.
  • Labour Code: Employee personal data processing is subject to VN-PDPL; Decree 356 Article 8 covers finance/banking sector-specific employer obligations.
  • GDPR comparison: VN-PDPL is broadly GDPR-inspired. Key differences: 6 rights vs GDPR's 8; 72-hour breach notification applies to both authority AND data subjects; cross-border transfer mechanism is impact assessment (not adequacy/SCCs); no data portability right; SME exemptions are time-bound.

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
  • 2018年网络安全法(第24/2018/QH14号法律): 越南PDPL是个人数据领域的特别法;网络安全法仍适用于更广泛的数据本地化及系统安全义务。
  • 消费者保护法: 越南PDPL规定的数据主体权利是对消费者权利的补充。
  • 劳动法: 员工个人数据处理需遵守越南PDPL;第356号法令第8条涵盖金融/银行业雇主的特定义务。
  • 与GDPR对比:越南PDPL广泛借鉴GDPR。主要差异:6项权利vs GDPR的8项;72小时泄露通知同时适用于主管机关和数据主体;跨境传输机制为影响评估(而非充分性认定/SCCs);无数据可携权;SME豁免有时间限制。

本技能提供一般性合规信息,而非法律建议。请对照官方来源核实当前要求;如需决策,请咨询合格律师或认证评估师。