進出・設立21 min read

Vietnam's Personal Data Protection Decree (PDPD): The Response for Japanese Companies

Vietnam's Personal Data Protection Decree (PDPD): The Response for Japanese Companies

Vietnam's Personal Data Protection Becomes a New Must-Do for Japanese Companies

For Japanese companies doing business in Vietnam, responding to personal data protection has become a management issue that can no longer be deferred. The decree on personal data protection that took effect in 2023 (Decree 13/2023/ND-CP, effective July 1, 2023, commonly known as the PDPD) introduced a comprehensive personal data protection framework into Vietnam for the first time, and furthermore, the preparation of a Personal Data Protection Law (PDPL) that elevates this framework to the level of a statute is advancing, making the discipline a notch stricter. The target is every company that handles the personal data of employees, customers, and business partners, and a delay in response becomes a risk to both administrative sanctions and reputation.

This article organizes, from the practical standpoint of Japanese companies, the overall picture of Vietnam's personal data protection system, lawful processing and obtaining consent, the handling of sensitive information, the discipline of cross-border data transfer, and the systems and filings that companies should put in place.

The Overall Picture of Vietnam's Personal Data Protection System

Vietnam's personal data protection has been operated with Decree 13/2023 at its core. This is a framework inspired by the EU's GDPR, stipulating the rights of data subjects, the obligations of processors, the discipline of cross-border transfer, and the system of impact assessment and filing. The competent authority is the Ministry of Public Security (especially the cybersecurity division), and it is also linked with the Law on Cybersecurity (2018). In recent years, the move to elevate this decree to a statute has advanced, in the direction of increasing the stability of the discipline and the effectiveness of penalties.

Classification of Personal Data

The system divides personal data into "basic personal data" and "sensitive personal data." Names, contact details, and the like are basic data; health, biometric, ideological/religious, financial, and location information and the like fall under sensitive data, and the processing of sensitive data is subject to stricter requirements. Taking inventory of which category the data your company handles falls into is the starting point of the response.

Personal data protection in Vietnam: the three response areas for Japanese companies

Lawful Processing and Obtaining Consent

The core of responding to personal data protection is to clarify "on what basis, and to what extent, may data be handled."

Obtaining Consent and Its Requirements

Vietnam's system emphasizes "consent" as the basis for legalizing the processing of personal data. Consent must be given explicitly, of free will, on the basis that the individual has clearly understood the purpose, scope, and method of processing. Vague blanket consent, or consent that is in substance coerced as a condition of using a service, carries a risk of having its validity contested. Obtaining, recording, and responding to the withdrawal of consent must be built into business processes.

The Rights of Data Subjects

The individual (data subject) is granted the rights to request access to, correction of, and deletion of their own data, restriction of and objection to processing, the halting of data provision, and so on. Companies must put in place a point of contact and procedures to respond to these requests within an appropriate period. Especially at BtoC companies with customer touchpoints, building a system for responding to inquiries is an urgent task.

Sensitive Information and Impact Assessment

Sensitive personal data and certain processing call for additional measures.

Data Processing Impact Assessment (DPIA)

Companies bear an obligation to prepare and retain a "data processing impact assessment (DPIA)" for the processing of personal data. This documents what kind of data, for what purpose, to where, and how it is transferred and stored, and what risks and countermeasures there are. Putting it in place so that it can be presented when requested by the authorities is the foundation of compliance.

Add-On Requirements for Sensitive Data

When handling sensitive data such as health, biometric, and financial data, the requirements for notifying the individual and obtaining consent become stricter, and a higher level of safety-management measures is demanded. Companies that handle HR (health information, payroll) or services involving payment and credit should design the handling of sensitive data separately. When taking over a target company's customer database through M&A, the lawfulness of its acquisition and use becomes an issue in due diligence. For details, please refer to "Legal due diligence in Vietnamese M&A."

The Discipline of Cross-Border Data Transfer

What has the greatest practical impact for Japanese companies is the discipline of the overseas transfer of personal data (cross-border transfer).

Impact Assessment and Filing of Cross-Border Transfer

When transferring personal data from Vietnam overseas, a company bears the obligation to prepare an impact assessment regarding cross-border transfer and to file it with the competent authority (the cybersecurity division of the Ministry of Public Security). The everyday operation of sending the employee and customer data of a Vietnam site to the Japanese head office's servers or to a global cloud or HR system falls under this cross-border transfer. The more a company uses the group's common IT infrastructure, the heavier the task of inventorying and documenting transfers becomes.

Consistency with Global Systems

Many Japanese companies operate HR, accounting, and customer management with systems integrated at the regional or global level. Leaving unaddressed a structure in which Vietnam's personal data flows into these systems can result in a state of violation—undeclared cross-border transfer. Visualizing the data flow and putting in place the basis, impact assessment, and filing for transfers is the key to reconciling global operation with local law.

The Systems and Filings Companies Should Put in Place

The essence of responding to the system is not merely to create documents, but to build a system that can be operated continuously.

Internal Systems, Regulations, and Training

Put in place, as internal regulations, a personal data protection policy, rules for acquisition, use, storage, and deletion, consent management, a point of contact for responding to data subjects, and incident-response procedures. Together with this, ensure operation on the ground through employee training. These should be designed as part of the overall governance of the local subsidiary, and it is effective to consider them integrated with the framework of "Vietnam subsidiary governance."

The Risk of Violation

Undeclared cross-border transfer, processing without consent, inadequate safety management, and leaving leaks unaddressed are subject to administrative fines or rectification orders, and damage the trust in the business. Penalties are trending toward strengthening, so standing on the premise that "operation is still lax" is dangerous. The realistic approach is to prioritize the response early and start from the high-risk areas (cross-border transfer, sensitive data, BtoC customer data).

Practical Impact That Differs by Industry

The burden of personal data protection differs greatly according to the type and volume of data handled. Assessing which profile your company is closest to clarifies the priorities.

The Case of Manufacturing (Primarily BtoB)

Manufacturing centered on factories, on one hand, has a relatively small volume of customer personal data; on the other, it holds a large volume of sensitive data—the HR data of employees (health information, payroll, evaluation). The greatest issue is the cross-border transfer of this employee data to the Japanese head office or a global HR system. The more a company uses the group's common HR platform, the more easily it falls into undeclared cross-border transfer, and inventorying the data flow and putting filings in place become urgent. Together with this, regarding the handling of data accompanying employees' joining, leaving, and evaluation, putting in place a framework of work rules and consent is required.

The Case of BtoC, E-Commerce, and Service Industries

BtoC companies that provide services to consumers and e-commerce operators continuously acquire and use a large volume of customer personal data. Managing the obtaining of consent and the scope of use becomes complex in aspects such as use for marketing purposes, provision to third parties (advertising and analytics operators), and tracking on apps and the web. The point of contact for responding to access and deletion requests from data subjects also tends to handle large volumes. Along with the expansion of the e-commerce market, the importance of this area is increasing, and behind the growth opportunities discussed in "Vietnam's e-commerce market 2026," data governance is becoming a precondition for business continuity.

Managing Outsourcing Partners and Cloud Operators

When you outsource the processing of personal data to an external party, the responsibility of the outsourcer does not disappear. You are required to root out the outsourcing partners and operators that touch personal data—payment agents, call centers, the cloud, SaaS, marketing support—and to stipulate in the contract the obligation of safety management, restrictions on re-outsourcing, and the obligation to report leaks. Especially when using overseas cloud or SaaS, because that itself can constitute cross-border transfer, you need to grasp the data-storage location and transfer route of the services you use. It is important to close the blind spot whereby data you think "our company does not handle directly" is in fact flowing overseas via an outsourcing partner.

Organizing the Response Areas: A Comparison Table

Below is an organized summary of the main response areas Japanese companies should tackle, from the perspectives of content, priority, and practical action.

Illustration of the priority of personal data protection responses

Response area

Main content

Practical action

Data inventory

Classification of basic / sensitive

Visualize the data held

Consent and rights response

Lawful processing basis

Consent management, request point of contact

DPIA

Documenting the processing impact assessment

Prepare and retain the assessment

Cross-border transfer

Filing of overseas transfer

Organize the data flow, file

Systems and training

Regulations, incident response

Internal regulations, employee training

Practical Points Japanese Companies Should Grasp

First, the starting point is data inventory. Unless you visualize whose data, of what kind, for what purpose, and where it is stored and transferred, you cannot draw the overall picture of the response. Second, cross-border transfer is the greatest issue for Japanese companies. You should prioritize the work of legalizing data transmission to the Japanese head office or a global cloud through impact assessment and filing. Third, because sensitive data (HR health information, payment and credit data) has add-on requirements, separate it and manage it strictly. Fourth, the system is in the midst of being strengthened from a decree to a statute, so having a system that can keep up with the latest discipline (updating regulations, clarifying who is responsible) supports long-term compliance.

Vietnam's personal data protection is a new must-do response area for Japanese companies, gaining effectiveness through elevation to the level of a statute, starting from Decree 13/2023. Solara & Co supports—with a team versed in the practice of both the Japanese and Vietnamese sides—everything from data inventory, the design of consent and data-subject responses, the impact assessment and filing of DPIA and cross-border transfer, to building internal regulations and a training system. We will propose, in line with your company's business reality, a realistic, clearly prioritized response plan that reconciles global operation with Vietnam's local law.

FAQ

Frequently asked questions

ベトナムの個人情報保護(PDPD)は何という法令ですか?

中核は2023年7月1日施行の個人データ保護に関する政令(Decree 13/2023/ND-CP、通称PDPD)です。ベトナムで初めて包括的な個人データ保護の枠組みを導入し、EUのGDPRに着想を得て、データ主体の権利・処理者の義務・越境移転の規律・影響評価と届出を定めています。所管は公安省のサイバーセキュリティ部門で、さらにこれを法律へ格上げする個人データ保護法(PDPL)の整備が進み、規律は強化の方向にあります。

日本本社へ従業員データを送るのは越境移転に当たりますか?

はい。ベトナム拠点の従業員・顧客の個人データを日本本社のサーバーやグローバルなクラウド・人事システムへ送ることは、個人データの国外移転(越境移転)に該当します。この場合、越境移転に関する影響評価書を作成し、所管当局へ届け出る義務があります。グループ共通のITインフラを使う日系企業ほど該当範囲が広く、データフローの棚卸しと移転の文書化・届出が実務上の最重要課題になります。

個人データ処理影響評価(DPIA)とは何ですか?

企業が、どのような個人データを、何の目的で、どこに、どのように移転・保管し、どんなリスクと対策があるかを文書化する『個人データ処理影響評価書』です。Decree 13/2023は、この評価書の作成と保管を企業の義務としています。当局から求められた際に提示できるよう整備しておくことがコンプライアンスの基盤で、とくに越境移転や機微データの処理では重要性が高まります。

基本個人データと機微個人データの違いは何ですか?

ベトナムの制度は個人データを二つに分類します。氏名・連絡先などが『基本個人データ』、健康・生体・思想信条・金融・位置情報などが『機微個人データ』です。機微データの処理には、本人への通知・同意取得の要件がより厳格になり、安全管理措置の水準も高く求められます。人事の健康情報や決済・与信を伴うデータを扱う企業は、機微データを切り分けて厳格に管理する設計が必要です。

個人情報保護に違反するとどうなりますか?

無届けの越境移転、同意なき処理、安全管理の不備、漏えいの放置などは、行政罰金や是正命令の対象となり、事業の信頼を損ないます。罰則は政令から法律への格上げを通じて強化の方向にあり、『まだ運用が緩い』という前提に立つのは危険です。まずデータの棚卸しを行い、リスクの高い領域(越境移転・機微データ・BtoC顧客データ)から優先的に対応に着手するのが現実的です。

Related

進出・設立

ベトナムのフランチャイズ進出:法規制と展開戦略

人口約1億人と中間層の拡大を背景に、ベトナムは外食・小売・サービスのフランチャイズ展開の有望市場です。商工省への登録制度、ブランドと品質を守る契約設計、直営・マスターFC・エリア開発という進出形態の選択、立地・ローカライズ戦略までを、日系ブランドの目線で体系的に解説します。

Solara編集部
進出・設立

ベトナムの債権回収と与信管理:契約から回収まで

ベトナムでは「売る力」より「回収する力」が利益を左右します。回収力は、取引前の与信管理、契約条項の作り込み、日常の債権モニタリング、滞納時の段階的対応という上流からの積み上げで決まります。与信から回収までを一気通貫で設計する考え方を、ベトナムの実務に即して解説します。

Solara編集部
進出・設立

ベトナム南部の工業団地:ホーチミン近郊の立地比較

成熟した産業集積、厚い消費市場への近接、豊富な労働力を武器に、ホーチミンを中心とする南部経済圏は国内で最もバランスのとれた製造拠点です。ビンズオン・ドンナイ・ロンアン・バリア=ブンタウ・タイニンといった主要集積地を産業・強み・留意点で比較し、深水港・空港・道路網のインフラと立地選定の判断軸、留意すべきリスクを実務目線で整理します。

Solara編集部

Free Consultation

From the earliest concept stage,
please feel free to reach out.

Under strict confidentiality, we offer a free initial consultation whether or not you have a specific deal in mind. Our specialist team walks with you from clarifying where to begin.

info@solara-c.comJapan (+81) 90-6748-3978Vietnam (+84) 356-234-492

ContactFeel free to reach out to us anytime.Contact usNewsletterVietnam market intelligence, delivered once every three months.Sign up for the newsletter