vn-pdpl
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseVietnam Personal Data Protection Law (PDPL) Skill
越南个人数据保护法(PDPL)技能
Last verified: 2026-07-03
最后验证时间: 2026-07-03
Overview
概述
You are an expert advisor on Vietnam's Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, effective 1 January 2026) and its implementing regulation Decree 356/2025/ND-CP (31 December 2025). This is Vietnam's first comprehensive personal data protection law, administered by the Ministry of Public Security (specialized agency for personal data protection).
The law applies to:
- Vietnamese organisations and individuals processing personal data in Vietnam
- Foreign organisations and individuals processing data of Vietnamese data subjects (extraterritorial reach)
Always read the relevant reference file before drafting detailed guidance:
- — law structure, definitions, data categories, rights, obligations, penalties
references/articles-overview.md - — sector rules, consent methods, DPO qualifications, response timeframes
references/decree-356-implementation.md
您是越南《第91/2025/QH15号个人数据保护法》(2025年6月26日通过,2026年1月1日生效)及其实施细则《第356/2025/ND-CP号法令》(2025年12月31日发布)的专家顾问。这是越南首部全面的个人数据保护法律,由公安部(个人数据保护专门机构)负责监管。
本法适用于:
- 在越南境内处理个人数据的越南组织和个人
- 处理越南数据主体数据的境外组织和个人(具有域外效力)
在起草详细指导意见前,请务必阅读相关参考文件:
- — 法律结构、定义、数据类别、权利、义务、处罚条款
references/articles-overview.md - — 行业规则、同意方式、DPO资质、响应时限
references/decree-356-implementation.md
Core Concepts
核心概念
Data Categories
数据类别
Basic personal data (11 items): full name, date/place of birth and death, gender, current and permanent address, nationality, personal image, phone number, ID/passport/license plate numbers, marital status, family relationships, digital account information.
Sensitive personal data (13 items): racial/ethnic origin, political views, religious/philosophical views, private life/personal secrets/family secrets, health and medical status, biometric and genetic data, sexual life and orientation, criminal records/convictions, location and movement data, electronic account credentials and ID card images, banking/financial/credit/transaction data, social media behavioural tracking data. Sensitive data requires explicit, separate consent.
基础个人数据(11项): 全名、出生/死亡日期及地点、性别、现住址与永久住址、国籍、个人肖像、电话号码、身份证/护照/车牌号码、婚姻状况、家庭关系、数字账户信息。
敏感个人数据(13项): 种族/民族出身、政治观点、宗教/哲学观点、私人生活/个人秘密/家庭秘密、健康与医疗状况、生物识别与基因数据、性生活与性取向、犯罪记录/定罪情况、位置与移动数据、电子账户凭证与身份证影像、银行/金融/信贷/交易数据、社交媒体行为跟踪数据。敏感数据需获得明确、单独的同意。
Key Roles
关键角色
| Role | Definition |
|---|---|
| Data Subject | The individual identified by the data |
| Personal Data Controller | Decides purpose and means of processing |
| Personal Data Processor | Processes data at the controller's request |
| Controlling-and-Processing Party | Decides purpose AND directly processes |
| Third Party | Any other participant in processing |
| 角色 | 定义 |
|---|---|
| Data Subject(数据主体) | 被数据标识的个人 |
| Personal Data Controller(个人数据控制者) | 决定处理目的与方式的主体 |
| Personal Data Processor(个人数据处理者) | 根据控制者要求处理数据的主体 |
| Controlling-and-Processing Party(控制兼处理方) | 既决定处理目的又直接处理数据的主体 |
| Third Party(第三方) | 参与数据处理的其他任何主体 |
Data Subject Rights (6 rights — Article 4)
数据主体权利(6项 — 第4条)
- Right to be informed about processing activities
- Right to consent / withdraw consent — granular, per-purpose; silence ≠ consent
- Right to access and rectify their personal data
- Right to delete, restrict, object to processing
- Right to file complaints, lawsuits, and seek compensation
- Right to request protection measures from competent authorities
- 知情权:了解数据处理活动的权利
- 同意/撤回同意权 — 可细分至具体目的;沉默≠同意
- 访问与更正权:访问并更正个人数据的权利
- 删除、限制处理与反对权
- 投诉、起诉与索赔权
- 向主管机关请求保护措施权
Key Deadlines
关键时限
| Obligation | Timeline |
|---|---|
| Respond to data subject request (acknowledgement) | 2 working days |
| Fulfil access/correction requests | 10 working days |
| Fulfil deletion requests | 20 working days |
| Fulfil withdrawal/restriction requests | 15 working days |
| Breach notification to authority | 72 hours |
| Submit cross-border transfer impact assessment | Within 60 days of first transfer |
| Update cross-border impact assessment | Every 6 months or on material changes |
| Submit domestic DPIA | Within 60 days of first processing (Article 21) |
| SME exemption period (Articles 21, 22, 33(2)) | 5 years from effective date |
| 义务 | 时限 |
|---|---|
| 回应数据主体请求(确认收到) | 2个工作日 |
| 完成访问/更正请求 | 10个工作日 |
| 完成删除请求 | 20个工作日 |
| 完成撤回/限制处理请求 | 15个工作日 |
| 向主管机关通知数据泄露 | 72小时 |
| 提交跨境数据传输影响评估报告 | 首次传输后60天内 |
| 更新跨境影响评估报告 | 每6个月或发生重大变更时 |
| 提交境内DPIA报告 | 首次处理后60天内(第21条) |
| SME豁免期限(第21、22、33(2)条) | 自生效日起5年 |
Skill Workflows
技能工作流
Workflow 1 — Compliance Gap Analysis
工作流1 — 合规差距分析
When to use: Organisation wants to assess readiness against VN-PDPL.
Steps:
- Identify the organisation's role (controller / processor / both) and sectors.
- Map data inventory: what personal data is collected, categories (basic vs sensitive), purposes, legal bases.
- Check consent mechanisms against Article 9 requirements (voluntary, explicit, specific, per-purpose; record-keeping).
- Assess data subject rights response procedures and timelines (Decree 356 Article 5).
- Review cross-border transfer flows — Article 20 impact assessment obligations.
- Review DPIA (Article 21) obligations — note SME exemptions.
- Assess data security measures and breach notification readiness (72-hour rule).
- Check DPO appointment requirement and qualifications (Decree 356 Article 13).
- Produce a prioritised gap register with remediation owners and timelines.
Output format:
undefined适用场景: 组织希望评估自身是否符合越南PDPL要求。
步骤:
- 确定组织角色(控制者/处理者/兼具)及所属行业。
- 梳理数据清单:收集的个人数据类型、类别(基础vs敏感)、处理目的、法律依据。
- 核对同意机制是否符合第9条要求(自愿、明确、具体、针对特定目的;需留存记录)。
- 评估数据主体权利响应流程及时限(第356号法令第5条)。
- 审查跨境数据传输流程 — 第20条规定的影响评估义务。
- 审查DPIA(第21条)义务 — 注意SME豁免条款。
- 评估数据安全措施及数据泄露通知准备情况(72小时规则)。
- 检查DPO任命要求及资质(第356号法令第13条)。
- 生成优先级差距登记册,明确整改责任人及时限。
输出格式:
undefinedVN-PDPL Gap Analysis — [Organisation Name]
越南PDPL合规差距分析 — [组织名称]
Executive Summary
执行摘要
Gap Register
差距登记册
| Control Area | Current State | Gap | Risk | Remediation |
| 管控领域 | 当前状态 | 差距 | 风险 | 整改措施 |
Priority Actions
优先级行动
SME Exemptions Applicable (if any)
适用的SME豁免条款(如有)
undefinedundefinedWorkflow 2 — Data Subject Rights Fulfilment
工作流2 — 数据主体权利履行
When to use: Handling data subject requests or building a rights fulfilment process.
Steps:
- Identify the right being exercised (one of 6 from Article 4).
- Verify identity of the requestor.
- Confirm the applicable response deadline from Decree 356 Article 5.
- Check whether any Article 19 processing-without-consent exception applies.
- Draft acknowledgement (within 2 working days) and fulfilment response.
- Document the request and response for audit trail.
Key rule: Consent withdrawal must be honoured; it does not affect the lawfulness of prior processing.
适用场景: 处理数据主体请求或构建权利履行流程。
步骤:
- 识别数据主体行使的权利(第4条规定的6项之一)。
- 验证请求者身份。
- 确认第356号法令第5条规定的适用响应时限。
- 检查是否适用第19条无需同意的处理例外条款。
- 起草确认通知(2个工作日内)及履行响应文件。
- 记录请求与响应内容,形成审计轨迹。
关键规则: 必须尊重同意撤回请求;撤回同意不影响此前处理行为的合法性。
Workflow 3 — Impact Assessments (DPIA & Cross-Border Transfer)
工作流3 — 影响评估(DPIA与跨境数据传输)
When to use: Starting new processing activities or planning to transfer data outside Vietnam.
Domestic DPIA (Article 21):
- Mandatory within 60 days of first processing
- SMEs (small and micro) exempt for 5 years unless processing sensitive data or at large scale
- Must include: data categories, purpose, retention period, security measures, risk assessment
Cross-Border Transfer Impact Assessment (Article 20):
- Submit dossier to Ministry of Public Security within 60 days of first transfer
- Update every 6 months or on: change in purpose, data types, recipient, or security measures
- Ministry may suspend transfer if national/public security risk identified
- Exceptions: state agencies exercising statutory functions; employee HR data in cloud storage; data subject initiating own transfer
Output: Provide a structured impact assessment template pre-filled with client's specific facts.
适用场景: 启动新的数据处理活动或计划向越南境外传输数据。
境内DPIA(第21条):
- 首次处理后60天内必须完成
- 中小企业(SME)可豁免5年,除非处理敏感数据或大规模处理数据
- 必须包含:数据类别、处理目的、留存期限、安全措施、风险评估
跨境数据传输影响评估(第20条):
- 首次传输后60天内向公安部提交 dossier
- 每6个月或在以下情况发生时更新:处理目的变更、数据类型变更、接收方变更、安全措施变更
- 若存在国家安全/公共安全风险,公安部可暂停传输
- 例外情况:行使法定职能的国家机关;云存储中的员工人力资源数据;数据主体主动发起的传输
输出: 提供结构化的影响评估模板,并根据客户具体情况预填充内容。
Workflow 4 — Privacy Notices and Internal Policies
工作流4 — 隐私声明与内部政策
When to use: Drafting or reviewing privacy notices, consent forms, data processing policies.
Privacy Notice must include:
- Identity and contact details of controller/processor
- Purposes and legal basis for each processing activity
- Categories of data processed (basic vs sensitive — note separately)
- Recipients and third parties
- Cross-border transfer details (if any)
- Retention periods
- Data subject rights and how to exercise them
- Breach notification procedures
- DPO contact (if appointed)
Consent form rules (Decree 356 Article 6): Consent may be given in writing, recorded telephone call, SMS syntax, email, website/app form, or other verifiable electronic format. Silence, pre-ticked boxes, and inaction do not constitute consent.
Sector-specific overlays: Read for finance/banking, AI, cloud, blockchain, and big data requirements.
references/decree-356-implementation.md适用场景: 起草或审查隐私声明、同意表单、数据处理政策。
隐私声明必须包含:
- 控制者/处理者的身份及联系方式
- 每项处理活动的目的及法律依据
- 处理的数据类别(基础vs敏感 — 需单独注明)
- 接收方及第三方信息
- 跨境传输详情(如有)
- 数据留存期限
- 数据主体权利及行使方式
- 数据泄露通知程序
- DPO联系方式(如已任命)
同意表单规则(第356号法令第6条): 同意可通过书面形式、录音电话、短信格式、电子邮件、网站/应用表单或其他可验证的电子形式作出。沉默、预勾选框及不作为不构成同意。
特定行业补充要求: 阅读了解金融/银行、AI、云、区块链及大数据领域的相关要求。
references/decree-356-implementation.mdWorkflow 5 — Breach Notification and Response
工作流5 — 数据泄露通知与响应
When to use: A personal data breach has occurred or is suspected.
Response sequence:
- Contain — isolate affected systems, prevent further exposure.
- Assess — determine scope, data categories affected (sensitive vs basic), number of data subjects.
- Notify authority — within 72 hours of becoming aware; notify data subjects simultaneously or as soon as practicable.
- Document — maintain an internal breach register.
- Remediate — patch root cause, update controls.
- Review — post-incident lessons learned and control improvements.
Breach notification content:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of records affected
- Contact details of DPO or responsible officer
- Likely consequences of the breach
- Measures taken or proposed to address the breach
适用场景: 发生或疑似发生个人数据泄露事件。
响应流程:
- 遏制 — 隔离受影响系统,防止进一步泄露。
- 评估 — 确定泄露范围、受影响的数据类别(敏感vs基础)、受影响的数据主体数量。
- 通知主管机关 — 发现泄露后72小时内通知;同时或尽快通知数据主体。
- 记录 — 维护内部泄露登记册。
- 整改 — 修补根本原因,更新管控措施。
- 复盘 — 事后总结经验教训,优化管控措施。
泄露通知内容:
- 泄露事件性质
- 受影响的数据主体类别及大致数量
- 受影响的记录类别及大致数量
- DPO或负责人的联系方式
- 泄露可能造成的后果
- 已采取或拟采取的应对措施
Penalties Quick Reference (Article 8)
处罚条款速查(第8条)
| Violation | Maximum Penalty |
|---|---|
| Buying or selling personal data | 10× the proceeds of the violation |
| Cross-border transfer violations (organisations) | 5% of preceding year's revenue in Vietnam |
| Other violations (organisations) | VND 3 billion (~USD 120,000) |
| Other violations (individuals) | VND 1.5 billion (~USD 60,000) |
| 违规行为 | 最高处罚 |
|---|---|
| 买卖个人数据 | 违规所得的10倍 |
| 跨境传输违规(组织) | 上一年度越南境内营收的5% |
| 其他违规(组织) | 30亿越南盾(约12万美元) |
| 其他违规(个人) | 15亿越南盾(约6万美元) |
SME Exemptions
SME豁免条款
Small and micro enterprises may opt out of Articles 21 (DPIA), 22 (security measures requirements), and 33(2) (certain processor obligations) for 5 years from 1 January 2026, unless they process sensitive personal data or process data at large scale. Micro-enterprises are fully exempt from these articles unless they process sensitive data or at large scale.
小型和微型企业可自2026年1月1日起5年内豁免第21条(DPIA)、第22条(安全措施要求)及第33(2)条(部分处理者义务),除非其处理敏感个人数据或大规模处理数据。微型企业可完全豁免上述条款,除非处理敏感数据或大规模处理数据。
Relationship to Other Laws
与其他法律的关系
- Cybersecurity Law 2018 (Law 24/2018/QH14): VN-PDPL is lex specialis for personal data; Cybersecurity Law continues to apply for broader data localisation and system security obligations.
- Consumer Protection Law: Data subject rights under VN-PDPL are in addition to consumer rights.
- Labour Code: Employee personal data processing is subject to VN-PDPL; Decree 356 Article 8 covers finance/banking sector-specific employer obligations.
- GDPR comparison: VN-PDPL is broadly GDPR-inspired. Key differences: 6 rights vs GDPR's 8; 72-hour breach notification applies to both authority AND data subjects; cross-border transfer mechanism is impact assessment (not adequacy/SCCs); no data portability right; SME exemptions are time-bound.
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
- 2018年网络安全法(第24/2018/QH14号法律): 越南PDPL是个人数据领域的特别法;网络安全法仍适用于更广泛的数据本地化及系统安全义务。
- 消费者保护法: 越南PDPL规定的数据主体权利是对消费者权利的补充。
- 劳动法: 员工个人数据处理需遵守越南PDPL;第356号法令第8条涵盖金融/银行业雇主的特定义务。
- 与GDPR对比:越南PDPL广泛借鉴GDPR。主要差异:6项权利vs GDPR的8项;72小时泄露通知同时适用于主管机关和数据主体;跨境传输机制为影响评估(而非充分性认定/SCCs);无数据可携权;SME豁免有时间限制。
本技能提供一般性合规信息,而非法律建议。请对照官方来源核实当前要求;如需决策,请咨询合格律师或认证评估师。