Vietnam's Decree 13/2023/ND-CP on personal data protection (effective 1 July 2023) creates new obligations for every organization that collects and processes personal data — from customer information to employee records. What should your business prepare?

What does Decree 13/2023 cover?
It is Vietnam's first comprehensive legal framework on personal data protection. In essence, it requires businesses to have a lawful basis (usually the data subject's consent) when collecting and processing personal data, to respect data-subject rights, and to apply appropriate data-protection measures.

Which businesses are affected?
Almost all of them. If your business stores customer lists, sends marketing email, manages HR records, or collects information via a website — you are processing personal data and fall within scope.

6 things a business should do
- Map your data: know what personal data you collect and store, and where.
- Obtain & keep proof of consent: when collecting data (forms, contracts, sign-ups).
- Secure the data: encryption, access permissions, multi-factor authentication (MFA).
- Access control & logging: who views/edits data, and when.
- A process for data-subject requests: access, correction, deletion of their data.
- An incident response plan: a procedure for when a data breach occurs.
The role of the cloud platform
Platforms like Google Workspace and Microsoft 365 support compliance in many ways: data encryption, multi-factor authentication, granular permissions, access logs and centralized data-governance tools. Using a reputable business platform instead of free email/storage is a foundational step for protecting personal data.

Standardize your security & data governance
Viet Nis deploys cloud platforms with encryption, MFA, permissions & logging — a foundation for compliance.


