Vietnam’s Law No. 91/2025/QH15 on Personal Data Protection (PDPL) was enacted on 26 June 2025 and takes effect on 1 January 2026. Decree No. 356/2025/ND-CP was promulgated on 31 December 2025 and serves as the guiding decree for the PDPL, taking effect on the same date. Decree 356 also formally replaces Decree No. 13/2023/ND-CP dated 17 April 2023. For consumer research teams, this change matters because it elevates requirements from decree-level provisions to statutory law. Preparing early is also a recurring message in market guidance that notes businesses should begin preparing now, even before the effective date.
To prepare a Vietnam personal data protection law research program, start with how the PDPL frames lawful processing. The PDPL and Decree 356 prescribe general principles that map directly to common research workflows. Personal data may only be collected and processed within a specific and clearly defined scope and purpose, and organizations must ensure accuracy and allow data to be corrected, updated, or supplemented when necessary. They should store personal data for a period appropriate to the purpose of processing, unless otherwise provided by law. The framework also calls for appropriate institutional, technical, and human measures, plus proactive prevention, detection, stopping, and strict handling of violations. Build these requirements into study protocols, consent language, respondent communications, and vendor instructions.
Design the Compliance Workstream Around Impact Assessments and Transfers
Decree 356 adds practical obligations that can affect research timelines, especially for international studies, cloud analytics, or offshore processing. It introduces mandatory data transfer impact assessment dossiers for organizations engaging in cross-border transfers. The rule is process-driven: the organization must prepare and submit a comprehensive assessment within 60 days from the start of the transfer via the Ministry of Public Security’s portal. Decree 356 also highlights preparation and submission of Data Protection Impact Assessments (DPIA) and Transfer Impact Assessments (TIA) in line with statutory requirements. For research, that means you should define when a project becomes a “transfer,” set internal triggers, and align project start dates, vendor onboarding, and fieldwork launch to the submission window.
Classification is another planning step that can change how you design sampling and data minimization. Vietnam’s Data Law took effect on 1 July 2025, and guidance notes the PDPL (effective in 2026) will establish a comprehensive personal data protection framework for the first time. Decision No. 20/2025/QD-TTg sets out what is “Core” and “Important” data under the Data Law. “Important” data includes non-public data on organisations and citizens comprising basic data of 100,000 or more Vietnamese citizens, sensitive data of 10,000 or more Vietnamese citizens, and data on bank accounts, payment history, or debt obligations. Research teams should use these thresholds and examples to stress-test whether a large panel, survey, or tracking study could intersect with regulated categories, then document controls accordingly.
Finally, make your operating model fit Vietnam’s broader, scattered legal landscape. Commentary on Vietnam’s data framework notes requirements are spread across several legislations and that Vietnam did not have its own comprehensive set of rules until 2023’s Decree 13. Beyond the PDPL and Decree 356, other general and sector-specific regulations still apply in parallel, including the Cybersecurity Law and the Data Law, which classifies data into “important data,” “core data,” and “other data.” Consumer research teams should map responsibilities across legal, research ops, IT, and vendors, and link them to where data is stored and processed. As contextual pressure builds, the Vietnam data center market was valued at USD 1.04 billion in 2025 and is expected to reach USD 3.19 billion by 2031, growing at a CAGR of 20.47%, underscoring why governance for storage, access, and transfer paths should be explicit in every study plan.
When do Vietnam’s PDPL and Decree 356 take effect for consumer research teams?
What replaces Decree 13/2023 for personal data protection compliance planning?
What is the key cross-border transfer requirement in Decree 356?
Which Data Law thresholds should researchers watch when handling large datasets?
How should teams approach Vietnam personal data protection law research without missing parallel obligations?