Vietnam's Personal Data Protection Becomes a New Must-Do for Japanese Companies
For Japanese companies doing business in Vietnam, responding to personal data protection has become a management issue that can no longer be deferred. The decree on personal data protection that took effect in 2023 (Decree 13/2023/ND-CP, effective July 1, 2023, commonly known as the PDPD) introduced a comprehensive personal data protection framework into Vietnam for the first time, and furthermore, the preparation of a Personal Data Protection Law (PDPL) that elevates this framework to the level of a statute is advancing, making the discipline a notch stricter. The target is every company that handles the personal data of employees, customers, and business partners, and a delay in response becomes a risk to both administrative sanctions and reputation.
This article organizes, from the practical standpoint of Japanese companies, the overall picture of Vietnam's personal data protection system, lawful processing and obtaining consent, the handling of sensitive information, the discipline of cross-border data transfer, and the systems and filings that companies should put in place.
The Overall Picture of Vietnam's Personal Data Protection System
Vietnam's personal data protection has been operated with Decree 13/2023 at its core. This is a framework inspired by the EU's GDPR, stipulating the rights of data subjects, the obligations of processors, the discipline of cross-border transfer, and the system of impact assessment and filing. The competent authority is the Ministry of Public Security (especially the cybersecurity division), and it is also linked with the Law on Cybersecurity (2018). In recent years, the move to elevate this decree to a statute has advanced, in the direction of increasing the stability of the discipline and the effectiveness of penalties.
Classification of Personal Data
The system divides personal data into "basic personal data" and "sensitive personal data." Names, contact details, and the like are basic data; health, biometric, ideological/religious, financial, and location information and the like fall under sensitive data, and the processing of sensitive data is subject to stricter requirements. Taking inventory of which category the data your company handles falls into is the starting point of the response.

Lawful Processing and Obtaining Consent
The core of responding to personal data protection is to clarify "on what basis, and to what extent, may data be handled."
Obtaining Consent and Its Requirements
Vietnam's system emphasizes "consent" as the basis for legalizing the processing of personal data. Consent must be given explicitly, of free will, on the basis that the individual has clearly understood the purpose, scope, and method of processing. Vague blanket consent, or consent that is in substance coerced as a condition of using a service, carries a risk of having its validity contested. Obtaining, recording, and responding to the withdrawal of consent must be built into business processes.
The Rights of Data Subjects
The individual (data subject) is granted the rights to request access to, correction of, and deletion of their own data, restriction of and objection to processing, the halting of data provision, and so on. Companies must put in place a point of contact and procedures to respond to these requests within an appropriate period. Especially at BtoC companies with customer touchpoints, building a system for responding to inquiries is an urgent task.
Sensitive Information and Impact Assessment
Sensitive personal data and certain processing call for additional measures.
Data Processing Impact Assessment (DPIA)
Companies bear an obligation to prepare and retain a "data processing impact assessment (DPIA)" for the processing of personal data. This documents what kind of data, for what purpose, to where, and how it is transferred and stored, and what risks and countermeasures there are. Putting it in place so that it can be presented when requested by the authorities is the foundation of compliance.
Add-On Requirements for Sensitive Data
When handling sensitive data such as health, biometric, and financial data, the requirements for notifying the individual and obtaining consent become stricter, and a higher level of safety-management measures is demanded. Companies that handle HR (health information, payroll) or services involving payment and credit should design the handling of sensitive data separately. When taking over a target company's customer database through M&A, the lawfulness of its acquisition and use becomes an issue in due diligence. For details, please refer to "Legal due diligence in Vietnamese M&A."
The Discipline of Cross-Border Data Transfer
What has the greatest practical impact for Japanese companies is the discipline of the overseas transfer of personal data (cross-border transfer).
Impact Assessment and Filing of Cross-Border Transfer
When transferring personal data from Vietnam overseas, a company bears the obligation to prepare an impact assessment regarding cross-border transfer and to file it with the competent authority (the cybersecurity division of the Ministry of Public Security). The everyday operation of sending the employee and customer data of a Vietnam site to the Japanese head office's servers or to a global cloud or HR system falls under this cross-border transfer. The more a company uses the group's common IT infrastructure, the heavier the task of inventorying and documenting transfers becomes.
Consistency with Global Systems
Many Japanese companies operate HR, accounting, and customer management with systems integrated at the regional or global level. Leaving unaddressed a structure in which Vietnam's personal data flows into these systems can result in a state of violation—undeclared cross-border transfer. Visualizing the data flow and putting in place the basis, impact assessment, and filing for transfers is the key to reconciling global operation with local law.
The Systems and Filings Companies Should Put in Place
The essence of responding to the system is not merely to create documents, but to build a system that can be operated continuously.
Internal Systems, Regulations, and Training
Put in place, as internal regulations, a personal data protection policy, rules for acquisition, use, storage, and deletion, consent management, a point of contact for responding to data subjects, and incident-response procedures. Together with this, ensure operation on the ground through employee training. These should be designed as part of the overall governance of the local subsidiary, and it is effective to consider them integrated with the framework of "Vietnam subsidiary governance."
The Risk of Violation
Undeclared cross-border transfer, processing without consent, inadequate safety management, and leaving leaks unaddressed are subject to administrative fines or rectification orders, and damage the trust in the business. Penalties are trending toward strengthening, so standing on the premise that "operation is still lax" is dangerous. The realistic approach is to prioritize the response early and start from the high-risk areas (cross-border transfer, sensitive data, BtoC customer data).
Practical Impact That Differs by Industry
The burden of personal data protection differs greatly according to the type and volume of data handled. Assessing which profile your company is closest to clarifies the priorities.
The Case of Manufacturing (Primarily BtoB)
Manufacturing centered on factories, on one hand, has a relatively small volume of customer personal data; on the other, it holds a large volume of sensitive data—the HR data of employees (health information, payroll, evaluation). The greatest issue is the cross-border transfer of this employee data to the Japanese head office or a global HR system. The more a company uses the group's common HR platform, the more easily it falls into undeclared cross-border transfer, and inventorying the data flow and putting filings in place become urgent. Together with this, regarding the handling of data accompanying employees' joining, leaving, and evaluation, putting in place a framework of work rules and consent is required.
The Case of BtoC, E-Commerce, and Service Industries
BtoC companies that provide services to consumers and e-commerce operators continuously acquire and use a large volume of customer personal data. Managing the obtaining of consent and the scope of use becomes complex in aspects such as use for marketing purposes, provision to third parties (advertising and analytics operators), and tracking on apps and the web. The point of contact for responding to access and deletion requests from data subjects also tends to handle large volumes. Along with the expansion of the e-commerce market, the importance of this area is increasing, and behind the growth opportunities discussed in "Vietnam's e-commerce market 2026," data governance is becoming a precondition for business continuity.
Managing Outsourcing Partners and Cloud Operators
When you outsource the processing of personal data to an external party, the responsibility of the outsourcer does not disappear. You are required to root out the outsourcing partners and operators that touch personal data—payment agents, call centers, the cloud, SaaS, marketing support—and to stipulate in the contract the obligation of safety management, restrictions on re-outsourcing, and the obligation to report leaks. Especially when using overseas cloud or SaaS, because that itself can constitute cross-border transfer, you need to grasp the data-storage location and transfer route of the services you use. It is important to close the blind spot whereby data you think "our company does not handle directly" is in fact flowing overseas via an outsourcing partner.
Organizing the Response Areas: A Comparison Table
Below is an organized summary of the main response areas Japanese companies should tackle, from the perspectives of content, priority, and practical action.

Response area | Main content | Practical action |
|---|---|---|
Data inventory | Classification of basic / sensitive | Visualize the data held |
Consent and rights response | Lawful processing basis | Consent management, request point of contact |
DPIA | Documenting the processing impact assessment | Prepare and retain the assessment |
Cross-border transfer | Filing of overseas transfer | Organize the data flow, file |
Systems and training | Regulations, incident response | Internal regulations, employee training |
Practical Points Japanese Companies Should Grasp
First, the starting point is data inventory. Unless you visualize whose data, of what kind, for what purpose, and where it is stored and transferred, you cannot draw the overall picture of the response. Second, cross-border transfer is the greatest issue for Japanese companies. You should prioritize the work of legalizing data transmission to the Japanese head office or a global cloud through impact assessment and filing. Third, because sensitive data (HR health information, payment and credit data) has add-on requirements, separate it and manage it strictly. Fourth, the system is in the midst of being strengthened from a decree to a statute, so having a system that can keep up with the latest discipline (updating regulations, clarifying who is responsible) supports long-term compliance.
Vietnam's personal data protection is a new must-do response area for Japanese companies, gaining effectiveness through elevation to the level of a statute, starting from Decree 13/2023. Solara & Co supports—with a team versed in the practice of both the Japanese and Vietnamese sides—everything from data inventory, the design of consent and data-subject responses, the impact assessment and filing of DPIA and cross-border transfer, to building internal regulations and a training system. We will propose, in line with your company's business reality, a realistic, clearly prioritized response plan that reconciles global operation with Vietnam's local law.



