Protecting personal data, therefore, is no longer solely a matter for the technology sector but has become an urgent requirement within a modern national legal system.
Establishing a robust legal foundation
The National Assembly’s passage of the Law on Personal Data Protection marked an important milestone, demonstrating the political determination of the Party and State to protect human rights, citizens’ rights, and individual privacy in the digital environment. However, according to Professor and Doctor of Law Do Van Dai, Vice Rector of the Ho Chi Minh City University of Law, for these legal provisions to be effectively enforced, further in-depth research is needed into violations, enforcement measures, the rights of data subjects, and the responsibilities of relevant parties.
Against the backdrop of rapid digital transformation, experts believe that current regulations do not yet fully reflect the specific characteristics and increasingly serious nature of violations involving personal data. Drawing on the experience of countries such as France, Russia, and Australia, Dr Tran Thanh Thao of the Faculty of Criminal Law at the Ho Chi Minh City University of Law has put forward a number of guiding recommendations.
First, separate offences concerning violations of personal data protection regulations should be established in the Criminal Code, affirming that personal data constitutes an independent legal object with distinct value and should be afforded commensurate protection. At the same time, provisions governing violations should cover the entire “life cycle” of data, from collection, use, and sharing to the deletion and destruction of data, thereby ensuring that legal risks are controlled at every stage. The expansion of the scope of criminal liability to include legal entities is also an essential requirement, consistent with international standards and the realities of violations today.
The legal framework for personal data protection has gradually been strengthened. The Law on Personal Data Protection took effect on January 1, 2026. The Government has also issued Decree No. 356/2025/ND-CP detailing a number of articles and implementation measures for the Law, together with Decree No. 330/2026/ND-CP on penalties for administrative violations in the fields of cybersecurity and personal data protection.
However, experts note that some relevant regulations still use the concept of “personal information,” which fails to fully cover the various forms and activities involved in the processing of “personal data” in the digital environment. The identification of violations, their severity, and the grounds for applying sanctions in certain cases also require more specific guidance to ensure consistent enforcement. These gaps could be exploited by individuals and groups to illegally collect, exchange, and trade data for use in fraud and the misappropriation of assets.
Sharing his views on the issue, Colonel Hoang Van Dinh, Head of the Department for Prevention and Control of High-Tech Crime under the Quang Ninh City Police, said that since the beginning of 2026, the city police had received, investigated, and dealt with 43 cases involving high-tech crime, up 23 cases from the same period in 2025. Most of these cases involved the illegal purchase, sale, collection, and use of personal data. To carry out their criminal activities, offenders often begin by exploiting social media, messaging platforms, e-commerce, and online payment services to gain access to and illegally collect personal information, using it to establish trust and carry out fraud and asset appropriation.
On these platforms, offenders heavily utilise artificial intelligence (AI), deepfakes, fake websites, and QR codes to impersonate individuals, steal personal data and information, and lure victims into making transactions. Alongside exploiting technology, scammers also take advantage of the carelessness and complacency of individuals and businesses to use various “tricks” to obtain personal information and authentication codes or induce victims to install applications from unknown sources. In particular, the illegal collection and trading of personal data, including bank accounts, SIM cards, and social media accounts, has enabled cybercriminals to develop highly personalised fraud schemes.
Bringing laws and decrees into everyday practice
The Law on Personal Data Protection and related decrees have taken effect, establishing a comprehensive and effective legal framework for protecting personal data rights. They clearly define the responsibilities of entities that control and process personal data and establish data subjects’ rights, including the right to be informed, the right to consent, the right to access data and the right to request its deletion.
However, some legal experts argue that the Law and its implementing decrees should not only focus on dealing with violations through administrative, criminal, and civil measures, but should also seek to protect the rights and legitimate interests of data subjects whose rights have been violated, and clarify the responsibilities of relevant parties.
Specifically, further research and additional provisions are needed to define violations involving such matters as the processing of sensitive data, cross-border data transfers, violations of data subjects’ rights, and the responsibilities of relevant parties. As for sanctions, a wider range of penalties should be established, including fines, revocation of licences, suspension of operations, confiscation, deportation, and criminal prosecution, together with higher and additional penalties for serious and particularly serious violations. Measures to remedy the consequences should also be added, such as requiring the deletion or destruction of data and the surrender of illicit profits. These measures would help enhance the effectiveness of personal data protection amid rapid digital transformation.
Vietnamese law already contains basic provisions on personal data protection from a civil-law perspective. However, mechanisms for dealing with civil violations still rely on traditional provisions under the current Civil Code and Civil Procedure Code, lacking specialised mechanisms and regulations tailored to the unique characteristics of personal data collection and protection.
Drawing on international experience, a number of specific recommendations and solutions could be put forward to improve the civil-law framework governing this area. These include refining regulations on determining damages and expanding the liability of personal data controllers and processors, particularly with regard to recognising agreements on estimated compensation for damages. More specific provisions should also be introduced on administrative violations concerning the protection of sensitive personal data associated with individual privacy rights. The responsibilities of State agencies should be determined in cases where such entities violate personal data protection requirements. In addition, administrative penalties for violations of personal data protection should continue to be strengthened and increased under relevant decrees.