Most conversations about Vietnam’s Law on Personal Data Protection (Law No. 91/2025/QH15 together with its guiding Decree No. 356/2025/ND-CP, both in force since January 1, 2026) (“PDP Law”) treat compliance as a project for the coming quarters — something to scope, budget, and eventually build. That framing is comfortable, but it is often wrong. The uncomfortable truth is that many companies are already unknowingly violating the PDP Law using systems they installed years ago, against deadlines that have already passed. We discuss three of the most common traps — not exotic edge cases, but everyday practices followed today by many organizations — and why each one now carries real financial and potential personal exposure.
Trap one: the terminal at the gate
Walk into almost any factory, office tower, or serviced building in Vietnam and you will find the same device at the entrance: a terminal that logs when employees and guests arrive and leave. It is one of the most widely deployed pieces of workplace technology and it often requires either biometric data, such as fingerprints, facial geometry or images of ID cards. These data are expressly classified as sensitive personal data, and so impose more demanding obligations under the PDP Law. Any company processing such data must obtain the person’s explicit, specific, voluntary and informed consent. Additionally, a Data Protection Impact Assessment must be prepared, maintained and submitted to the authority for evaluation.
Both conditions are harder to meet than they look. Consent obtained in the employment context is legally fragile precisely because the relationship is unequal — an employee who must scan a fingerprint to be paid has not, in any meaningful sense, volunteered. In addition, a satisfactory Data Protection Impact Assessment requires a company to appoint data protection personnel, disclose measures/policies implemented to protect personal data and provide high-level diagrams of its data flows.
The practical consequence is stark: a great many employers in Vietnam are processing sensitive biometric data today without a defensible legal basis, without the satisfactory impact assessment the law requires, and without necessary consent. Most people do not make note of it, because the timekeeping terminal has been humming away, unremarked, since long before anyone had heard of the PDP Law.
Trap two: the cloud your business already runs on
Ask a compliance officer whether the company transfers personal data outside Vietnam and the reflexive answer is almost always no. A more revealing question is where the company’s email, customer database, HR system, and helpdesk actually reside. Microsoft 365, Google Workspace, Salesforce, AWS, and the rest of the standard corporate toolkits all run on servers located outside Vietnam. Every time an employee’s or customer’s personal data moves onto one of those platforms, it leaves the country. Under the PDP Law, that is a cross-border transfer of personal data, whether or not the company characterizes it that way.
A cross-border transfer is not prohibited, but it is conditioned (in most circumstances). The PDP Law requires a Cross-Border Transfer Impact Assessment, prepared and retained by the organization, with one original copy submitted to the Department of Cybersecurity and High-Tech Crime Prevention under the Ministry of Public Security (A05), together with the safeguards and documentation the assessment is meant to evidence. The consequences of non-compliance are material: unauthorized cross-border transfers can expose an organization to fines of up to five percent of its total revenue for the preceding financial year.
The gap here is between what counsel understands the company to do, and what its everyday software stack has quietly been doing all along. For many businesses, the finding on inspection will reveal the same pattern: the data has been crossing the border for years, and no assessment was ever filed.
Trap three: the sixty-day clock that has already run
Both the Data Protection Impact Assessment and the Cross-Border Transfer Impact Assessment must be submitted to the A05 within sixty days of the processing date, or as soon as the first cross-border transfer begins. For processing already underway when the law took effect on January 1, 2026, the prudent reading of the law is that the clock started then. If so, this means that for most companies the sixty-day window closed at the beginning of March 2026. The Law compounds the point by requiring these dossiers to be reviewed and refreshed every six months whenever purposes, controllers, processors, or third parties change.
This is why accommodating the new legal regime is not only a full planning exercise, but also remediation. A company that has not filed a Cross-Border Transfer Impact Assessment is not simply approaching a deadline; it has missed one. The correct posture is not really “when do we need to be ready,” but “how quickly can we close a gap that is already open.” Priorities will require addressing the highest-risk processing (biometrics, financial data, large-scale customer databases, offshore transfers). A documented good-faith remediation path should be crafted for compliance and can be shown to the authorities if they come asking. Penalties can be severe: individuals, not only entities, are exposed under this law, with personal fines reaching half the corporate amount and criminal liability available for the most serious misuses of data. The name on the compliance filing is that of a real person, and that person is increasingly the general counsel or the appointed data protection officer. This is not to say that these individuals are automatically liable for the company’s breaches; personal exposure generally arises only where an individual has personally committed, directed, or acquiesced in the violation. But it does mean the regime is no longer one that lives entirely at the entity level. Individuals whose names appear on filings have a direct interest in ensuring those filings are made.
What this means for the in-house lawyer
A manufacturer with a fingerprint clock, a services firm running on Microsoft 365, a retailer with a customer list in a cloud CRM — each is already inside the scope of Vietnam’s new data regime, and each may currently be out of compliance. The action required is unglamorous but urgent: to inventory what personal data the company holds and where it flows, identify the sensitive and cross-border processing (that carries the steepest penalties), establish an alternative lawful basis where any old consent will not hold, file overdue assessments, and stand up a data protection function that can keep the paperwork current. Vietnam’s market remains as attractive as ever. But the price of operating in it now includes treating personal data as a governed liability rather than a free input and the companies that recognize how little runway they actually have will be the ones that avoid becoming the enforcement authority’s first examples.
