After a decade in SEO, content, and AI-assisted marketing, I have watched Vietnamese teams happily paste customer lists, survey exports, and CRM data into ChatGPT, Claude, and a dozen no-code tools — without realising that, as of 1 January 2026, much of that is now a regulated activity with real fines attached. Vietnam’s Personal Data Protection Law (PDPL) is live. This is the plain-English version of what every marketing team — Vietnamese or foreign — actually needs to do.

Quick answer

Vietnam’s Personal Data Protection Law (PDPL) took effect on 1 January 2026, with Decree 356/2025/NĐ-CP replacing the older Decree 13/2023. For marketers, three things now matter most: (1) you need a lawful basis (usually consent) to use personal data for marketing; (2) sending personal data to foreign AI tools like ChatGPT, Claude, or Gemini counts as a cross-border data transfer that must be documented; and (3) penalties are now severe — up to VND 3 billion for many violations, and up to 5% of prior-year revenue for cross-border breaches. Anonymise data before feeding it to AI, and keep a consent record for every contact.

1 Jan 2026
PDPL in force
VND 3 tỷ
Max fine, many breaches
5%
Of revenue: cross-border
10×
Gain: illegal data sale

What actually changed in 2026?

Vietnam already had data-protection rules under Decree 13/2023/NĐ-CP, effective 1 July 2023. The 2026 shift is bigger: personal data protection is now governed by a full Law (passed in 2025, effective 1 January 2026), and Decree 356/2025/NĐ-CP replaces Decree 13 to provide the operational detail. A law sits higher than a decree, carries heavier penalties, and signals that enforcement is no longer theoretical. For a marketing team, the practical message is simple: the data you collect, store, segment, and feed into tools is now a compliance asset, not a free-for-all.

“The teams that get hurt won’t be the ones doing something obviously shady. They’ll be the ones who pasted a full customer export into a foreign AI tool to ‘write better emails’ — and never recorded consent or thought of it as a cross-border transfer.”

The five concepts every marketer must understand

Consent (sự đồng ý)

Marketing use of personal data generally needs clear, specific, informed consent. Pre-ticked boxes and vague “we may contact you” lines don’t cut it. Consent must be as easy to withdraw as to give.

Cross-border transfer

Sending personal data outside Vietnam — including into US-hosted AI tools — is a regulated transfer requiring a documented impact assessment. This is the rule marketers break most often, by accident.

Impact assessment (DPIA)

Processing and cross-border transfers require a written assessment file documenting what data you handle, why, and how it’s protected. It must be ready for the authority on request.

Data subject rights

Customers can access, correct, delete, and object to processing of their data, and withdraw consent. Your unsubscribe and data-deletion process must actually work.

Sensitive data

Health, financial, location, and similar categories get extra protection. Avoid collecting them for marketing unless you truly need them — and never paste them into a public AI tool.

Why AI tools are the new privacy minefield

Here is the part most Vietnamese marketing teams miss. The moment you copy a customer’s name, phone number, email, or order history into ChatGPT, Claude, Gemini, or a foreign automation tool, you have likely done two regulated things at once: processed personal data and transferred it across the border. Most popular AI tools run on servers in the US or EU. “I was just asking it to clean up my spreadsheet” is not a defence.

Lower risk
  • Anonymise/pseudonymise before pasting (replace names with “Customer A”)
  • Use AI for ideas, drafts, and analysis on aggregate data
  • Choose tools with a Vietnam data-residency or enterprise no-training option
  • Get consent that explicitly covers AI-assisted processing
  • Keep a written record of which tools touch personal data
High risk
  • Pasting a full CRM/customer export into a public chatbot
  • Uploading lead lists with names + phones for “enrichment”
  • Feeding customer support transcripts into untracked tools
  • Using AI on health, financial, or ID data for targeting
  • No consent record, no cross-border transfer documentation

What are the penalties under the PDPL?

Violation Indicative penalty
Unlawful cross-border data transfer From VND 3 billion up to 5% of prior-year revenue
Illegal sale or purchase of personal data Minimum VND 3 billion, up to 10× the illegal gain
Other violations Up to VND 3 billion
Individuals (vs. organisations) Roughly half the organisational fine

Figures are indicative and based on published summaries of the PDPL and Decree 356/2025. This article is practical guidance, not legal advice — confirm specifics with a Vietnamese data-protection lawyer before relying on them.

A 6-step compliance sprint for marketing teams

1
Map your data. List every place customer data lives — CRM, email tool, ad platforms, spreadsheets, AI tools. You can’t protect what you haven’t mapped.
2
Fix your consent capture. Update web forms, lead magnets, and Zalo/Facebook opt-ins so consent is explicit, specific, and logged with a timestamp.
3
Audit your AI tools. For each AI/automation tool, ask: does personal data go in? Where are its servers? Is there an enterprise no-training plan? Document the answers.
4
Adopt an anonymise-first rule. Make it a team standard: strip names, phones, and IDs before any data touches a public AI tool. Train the rule until it’s automatic.
5
Write the assessment file. Prepare a processing and cross-border transfer impact assessment, in Vietnamese, ready to show the authority. Get legal to review it.
6
Make deletion real. Test that unsubscribe, data-access, and deletion requests actually flow through every system — including your AI tools’ history.
Key takeaways
  • The PDPL is live as of 1 January 2026; Decree 356/2025 replaced Decree 13/2023.
  • Marketing use of personal data needs a lawful basis — usually explicit, logged consent.
  • Putting personal data into foreign AI tools is a cross-border transfer that must be documented.
  • Anonymise first — it’s the single easiest habit that removes most of the risk.
  • Penalties reach VND 3 billion, or 5% of revenue for cross-border breaches.

Privacy doesn’t mean abandoning AI — it means using it deliberately. If you’re still building your toolkit, start with our complete AI marketing stack for Vietnam, and read our practical playbooks for Claude, ChatGPT, and Gemini — each has different data-handling settings worth checking.

About SMK Vietnam: SMK Vietnam is a marketing hub helping Vietnamese companies and foreign brands (US, Japan, Thailand, Korea, Europe) run effective, compliant marketing in Vietnam — combining AI tools with local market expertise.

Want privacy-safe AI marketing in Vietnam?

We’ll help you map your data, set guardrails for AI tools, and keep your marketing both effective and PDPL-compliant.

Talk to SMK Vietnam →

Frequently asked questions

Is it illegal to use ChatGPT or Claude for marketing in Vietnam?

No — using AI tools is legal. What’s regulated is putting personal data into them. Use AI freely for ideas, drafts, and analysis on anonymised