Vietnam's Personal Data Protection Law 2025 (PDPL), enacted as Law No. 91/2025/QH15 on June 26, 2025, and effective from January 1, 2026, represents an upgrade from Decree 13/2023/ND-CP, establishing a comprehensive legal framework for the collection, use, disclosure, storage, transfer, and protection of personal data in Vietnam.
The core purposes of PDPL are as follows:
The PDPL applies broadly to all personal data processing activities within Vietnam, covering the following:
Article 8 of the PDPL introduces a tiered framework for maximum administrative penalties on personal data violations.
Key Penalty Highlights
Learn how Thales helps organizations comply with Vietnam’s PDPL through encryption, IAM, data monitoring, and compliance controls.
Thales’ solutions enable organisations in Vietnam to comply with PDPL, particularly Chapters I, II, and III, by enhancing governance over data protection with comprehensive visibility, control, and automation. Building on the PDPL’s foundational requirements, Decree No. 356/2025/ND-CP – released on December 31, 2025 – provides further details on personal data classification and cross-border data transfer. Thales supports organisations in aligning with both the PDPL and Decree 356, helping streamline compliance processes and ensure adherence to Vietnam’s evolving regulatory framework for data protection. These capabilities also support organisations in meeting the security and data governance expectations introduced by Vietnam’s Law on Artificial Intelligence (No. 134/2025/QH15), by protecting sensitive data used in AI systems through strong encryption, access controls, and data activity monitoring.
PDPL Compliance Solutions
Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, security for APIs, and a secure Content Delivery Network (CDN).
Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.
Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.
Data Security
Identity & Access Management
Data Security
Identity & Access Management
Data Security
Data Discovery & Classification
Identity & Access Management