Therefore, protecting personal data is no longer solely a matter for the technology sector but has become an urgent requirement within a modern country’s legal system.
Creating strong legal foundation
The National Assembly’s passage of the Law on Personal Data Protection marked an important milestone, demonstrating the political determination of the Party and State to protect human rights, citizens’ rights, and individuals’ right to privacy in the digital environment. However, according to Prof, Dr Do Van Dai, Vice President of the Ho Chi Minh City University of Law, further in-depth research is needed into violations, handling measures, the rights of data subjects, and the responsibilities of relevant parties to ensure that legal provisions are effectively enforced.
In light of the rapid development of digital transformation, the expert said that current regulations do not yet fully reflect the specific characteristics and increasingly serious nature of violations involving personal data. Drawing on experience from countries such as France, Russia, and Australia, Dr Tran Thanh Thao of the Faculty of Criminal Law at the Ho Chi Minh City University of Law has put forward a number of recommendations for consideration.
First, separate offences concerning violations of personal data protection regulations should be established in the Penal Code, affirming that personal data constitutes an independent legal interest with its own value and therefore requires commensurate protection. In addition, provisions on violations should cover the entire “life cycle” of data, from collection, use, and sharing to the deletion and destruction of data, thereby ensuring that legal risks are controlled at every stage. At the same time, expanding the scope of criminal liability to cover legal entities is an inevitable requirement, consistent with international standards and current patterns of violations.
The legal framework for personal data protection has been progressively strengthened. The Law on Personal Data Protection took effect on 1 January 2026. The government issued Decree No. 356/2025/ND-CP detailing a number of articles of the Law and measures for its implementation, as well as Decree No. 330/2026/ND-CP stipulating administrative penalties for violations in the fields of cybersecurity and personal data protection.
However, according to experts, some relevant regulations still use the concept of “personal information” and do not fully cover the forms and activities involved in processing “personal data” in the digital environment. In some cases, the identification of violations, their severity, and the grounds for applying sanctions also require more specific guidance to ensure consistent enforcement. Such gaps could be exploited by individuals and organisations to illegally collect, exchange, and trade data for use in fraud and property appropriation.
Speaking on the issue, Colonel Hoang Van Dinh, Head of the High-Tech Crime Prevention and Control Division of the Quang Ninh City Police, said that since the beginning of 2026, the city police had received, investigated, and dealt with 43 cases involving high-tech crime, marking an increase of 23 cases compared with the same period in 2025. Most of these cases involved the illegal trading, collection, and use of personal data. To commit offences, perpetrators often begin by exploiting social media, messaging platforms, and e-commerce and online payment services to gain access to and illegally collect personal information, which is then used to establish trust before carrying out fraud and appropriating assets.
On these platforms, perpetrators make extensive use of artificial intelligence (AI), deepfakes, fake websites, and QR codes to impersonate individuals, steal personal data and information, and lure victims into making transactions. Alongside exploiting technology, fraudsters also take advantage of the carelessness of individuals and businesses to use various “tricks” to obtain personal information and authentication codes or induce victims to install applications from unknown sources. In particular, illegal collection and trade of personal data such as bank account details, SIM cards, and social media accounts has enabled cybercriminals to develop highly personalised fraud scenarios.
Turning laws and decrees into practice
The Law on Personal Data Protection and relevant decrees have taken effect, helping establish a comprehensive and effective legal framework for protecting personal data rights. They clearly stipulate the responsibilities of parties that control and process personal data and establish data subjects’ rights, including the right to be informed, the right to consent, the right to access data, and the right to request its deletion.
However, some legal experts argue that the law and decrees should not merely focus on dealing with violations through administrative, criminal or civil measures, but they should also aim to protect the rights and legitimate interests of data subjects whose rights have been violated and clarify the responsibilities of relevant parties.
Specifically, further research and additional provisions are needed to identify violations involving such matters as the processing of sensitive data, cross-border data transfers, violations of data subjects’ rights, and the responsibilities of relevant parties. In terms of sanctions, a wider range of penalties should be available, including fines, revocation of licences, suspension, confiscation, deportation, and criminal prosecution, while fines and additional penalties should be increased for serious and particularly serious violations. At the same time, remedial measures should be added, such as requiring the deletion or destruction of data and the disgorgement of unlawful profits. These measures would improve the effectiveness of personal data protection amid rapid digital transformation.
Vietnamese law already contains basic provisions on personal data protection from a civil-law perspective. However, mechanisms for dealing with civil violations continue to rely on traditional provisions of the current Civil Code and Civil Procedure Code, without specific mechanisms and provisions for dealing with violations involving the particular circumstances of personal data collection and protection.
Prof, Dr Phan Hoai Nam,
Deputy Head of the Faculty of International Law at the Ho Chi Minh City University of Law
Prof, Dr Phan Hoai Nam, Deputy Head of the Faculty of International Law at the Ho Chi Minh City University of Law, said that Vietnamese law already contains basic provisions on personal data protection from a civil-law perspective. However, current mechanisms for dealing with civil violations still rely on traditional provisions of the current Civil Code and Civil Procedure Code, without specific mechanisms and provisions for handling violations involving the particular circumstances of personal data collection and protection.
Drawing on international experience and practices in other countries, several specific recommendations and solutions could be proposed to improve the civil-law framework governing this area. These include refining provisions on determining damages and expanding the liability of personal data controllers and processors, particularly regarding the acceptance of agreements on estimated compensation for damages.
More specific provisions should also be introduced concerning administrative violations involving the protection of sensitive personal data and their connection with individuals’ right to privacy. The responsibilities of state agencies should be established in cases where such entities violate personal data protection requirements. In addition, administrative penalties for violations of personal data protection should continue to be strengthened and increased in relevant decrees.