1. Introduction
 

FPT Software Company, Ltd. ("FPT Software" hereinafter) Corporate Data Protection Policy, privacy statement, procedures, guidelines, and templates lay out strict requirements for processing personal data pertaining to customers, business partners, employees or any other individual. It meets the requirements of the European Data Protection Regulation/Directive, PDPD356 VN, PDPL91 VN as well as other national Data Protection Regulations and ensures compliance with the principles of national and international data protection laws in force all over the world. The policy, privacy statement, procedures, guidelines, and templates set a globally applicable data protection and security standard for FPT Software and regulates the sharing of information between FPT Software, subsidiaries, legal entities, and partners. FPT Software have established guiding data protection principles – among them transparency, data economy and data security – as FPT Software guidelines.  

 
1.1. Purpose
 

The FPT Software Personal Data Handbook including the Protection Policy, Policy_Personal Data Protection Management_v3.7 and Policy_Cookie_Statement_v1.0 and privacy statement applies worldwide to FPT Software, Subsidiaries as well legal entities and is based on globally accepted, basic principles on data protection. Ensuring data protection is the foundation of trustworthy business relationships and the reputation of the FPT Software as a first-class employer.  

The Data Protection Policy provides one of the necessary framework conditions for cross-border data transfer among FPT Software, Subsidiaries, and legal entities. It ensures the adequate level of data protection prescribed by the European Union General Data Protection Regulation, APPI, PDPA, PDPD356 VN, PDPL91 VN or other national Personal Data Protection Regulations and the national laws for cross-border data transmission, including in countries that do not yet have adequate data protection laws. 

To standardize the collection, processing, transfer, and use of personal data, and promote the reasonable, lawfully, fairly, and transparent use of personal data to prevent personal data from being stolen, altered, damaged, lost or leaked, FPT Software establishes the personal data protection management policy, Data Protection Handbook, Cookie Statement, and information security policies.


1.2. Application Scope


Cookies used on fptsoftware.com 

 
1.3. Application of national Laws
 

The Data Protection Policy, privacy statement, procedures, guidelines, and templates comprise the internationally accepted data privacy principles without replacing the existing national/international laws. It supplements the national data privacy laws. The relevant national law will take precedence in the event that it conflicts with the Data Protection Policy and guidelines, or it has stricter requirements than this Policy and guidelines. The content of the Data Protection Policy, procedures and guidelines must also be observed in the absence of corresponding national legislation. The reporting requirements for data processing under national laws must be observed. 


Each subsidiary or legal entity of FPT Software is responsible for compliance with the Data Protection Policy, this privacy statement, guidelines, and the legal obligations. If there is reason to believe that legal obligations contradict the duties under the Data Protection Policy, privacy statement, procedures or the guidelines, the relevant subsidiary or legal entity must inform the Global Data Protection Officer. In the event of conflicts between national legislation, the Data Protection Policy, and this privacy statement, FPT Software will work with the relevant subsidiary or legal entity of FPT Software to find a practical solution that meets the purpose of the Data Protection Policy, guidelines, and this procedure. 


1.4. Responsibilities
 

The Global Data Protection Officer is responsible for ensuring that the privacy statement is correct and that mechanisms exist such as having the privacy statement on FPT Software website to make all data subjects aware of the contents of this notice prior FPT Software commencing collection of their data. 


The Global Data Protection Officer is responsible for ensuring that this statement is made available to data subjects prior to FPT Software collecting/processing their personal data.


All Employees/Staff of FPT Software who interact with data subjects are responsible for ensuring that this statement is drawn to the data subject’s attention and their consent to the processing of their data is secured.


2. Cookie 
 

FPT Software is part of FPT Corporation (FPT – HoSE) – the global leading technology and IT services group headquartered in Vietnam with nearly US$1.2 billion in revenue and 40,000 employees. Qualified with CMMI Level 5 & ISO 27001:2022, ISO 27701:2019, ASPICE LEVEL 3, FPT Software delivers world-class services in Smart factory, Digital platform, RPA, AI, IoT, Enterprise Mobilization, Cloud, AR/VR, Embedded System, Managed service, Testing, Platform modernization, Business Applications, Application Service, BPO and more services globally from delivery centers across the United States, Japan, Europe, Australia, Vietnam and the Asia Pacific.


Personal data type
Source (FPT Software obtained the personal data from if it has not been collected directly from you, the data subject.)

Name, email address, designation, company, country and telephone number

FPT Software WEB page

IP address, demographics, your device operating system, and browser type

FPT Software WEB page


Personal Information we may collect and process

You can assess or visit our website at any time without informing us who you are or providing us any personal information. However, we may collect information at our websites in two ways: (1) directly (for example, when you provide information, such as your name, email address, designation, company, country and telephone number, to sign up for a newsletter or register to comment on a forum website); and (2) indirectly (for example, through our website’s technology, we may collect certain information such as your IP address, demographics, your computers’ operating system, and browser type in case you give us consent for these information).


We do not attempt to track your personal information in order to identify you, but gathering these contact information in order to make up the web traffic routing, to diagnose problems with server for administration of our website, to better understand how you interact with our website and services and to re-design and upgrade the website for better use. If you choose not to provide your personal information that is mandatory to process your request, we may not be able to provide the corresponding service.

 


Use of collected information

We use personal data to provide you with information you request, process online job applications, and for other purposes which we would describe to you at the point where it is collected or which will be obvious to you. For example:

  • To further fulfil your requirements on products and services
  • To contact you with the aim of developing a business relationship
  • To feedback to your idea and/or to provide you relevant information at your requirements
  • To contact you for marketing purpose such as customer surveys
  • To inform you about our company
  • To obey regulations in applicable laws



Consent

By consenting to this Cookie Statement, you are giving us permission to process your personal data specifically for the purposes identified.


Consent is required for FPT Software to process personal data, but it must be explicitly given. Where we are asking you for personal data, we will always tell you why and how the information will be used. 


Means: FPT Software will inform you about the purpose of the processing, contact details of the Data controller or its representative, lawful basis of the processing, personal data was obtained, if not obtained directly from the data subject.


FPT Software provide updated information without any undue delay and before continuing with the processing if the purposes for the processing of the personal data are changed or extended. In this case FPT Software will ask for a new consent.


You may withdraw consent at any time by email, a written letter or telephone call to our Global Data Protection Officer or local subsidiary in line with our Procedure Withdrawal of Consent (Procedure_Consent Withdrawal_V1.6). Retrieve a copy of guideline and procedure Global Data Protection Officer, published on fptsoftware.com).



Data recipients, transfer, and disclosure of personal information

We do not share your personal information with third parties without seeking your prior permission, except as otherwise permitted or required under applicable law. We will seek your consent prior to using or sharing personal information for any purpose beyond the requirement for which it was originally collected. However, we may share your personal information within FPT Software or with any of its subsidiaries, business partners, service vendors, authorized third-party agents, or contractors located in any part of the world for the purposes of data processing, storage, or to provide a requested service or transaction, after ensuring that such entities are contractually bound by data privacy obligations. When required, we may disclose personal information to external law enforcement bodies or regulatory authorities, in order to comply with legal obligations to support our marketing effectiveness, FPT Software integrates with the LinkedIn Conversion API, allowing us to analyze opportunities and improve campaign performance. In this context, certain pseudonymized personal data (e.g., hashed email) may be shared with LinkedIn Corporation. Data is transferred securely and processed solely for conversion tracking and analytics. We maintain full compliance with data protection laws and uphold all data subject rights.


We do not intend for our websites or online services to be used by anyone under the age of 13. If you are a parent or guardian and believe we may have collected information about a child, please contact us as described in this Cookie Statement. 


FPT Software considers that, as a general rule, a child of 16 and over is mature enough to understand giving of consent, they are giving and should be in a position to give that consent. All Data subjects will be required to verify their identity. Where personal data is sought in respect of a child below the age of 16, a parent or guardian must give the consent on behalf of the child. Any response will be directed to the parent or guardian. FPT Software will need to be satisfied as to the identity of the parent or guardian, and that they are acting in the best interests of the child, before excepting the consent in respect of the child. Parent or guardian has the obligation to explain the process and the content to the child and if it is legally required (PDPD356 VN, PDPL91 VN) to get the consent of a child, it is parent, agent or guardian responsibility. 


If parent applying on behalf of a child under 16 years of age, FPT Software will require proof of identity and address of parent and that of the child, together with the birth certificate of the child.
If a legal guardian applying on behalf of a child under 16 years of age, FPT Software will require proof of guardian identity and address and that of the data subject, together with proof of authority to act as legal guardian and the birth certificate of the child.


If you are an agent acting on someone’s behalf (e.g. a solicitor applying on behalf of a client), FPT Software may require proof of agent identity and address and that of the data subject, and proof that the data subject has given consent to act on their behalf.


Disclosure

FPT Software will pass on your personal data to third parties.

 
Third country (non-EU) / international organisation
Safeguards in place to protect your personal data
Retrieve a copy of the safeguards in place here:
 

FPT Corporation 

FPT Software subsidiaries and legal entities globally

Business partners, service vendors, authorized third-party agents, or contractors

External law enforcement bodies or regulatory authorities

Processing agreement including Standard Contract Clause, Model Contract Clause and Transfer Impact Assessment

Global Data Protection Officer


Retention period

FPT Software will process personal data for one year. Retention period 2 years or based on applicable national laws/regulations (reference: Guideline_Personal Data Retention_v3.7, Procedure_Retention of Records_v1.6. Retrieve a copy of guideline and procedure Global Data Protection Officer, published on fptsoftware.com). 

Cookies policy

FPT Software understand that your privacy is important to you and is committed to being transparent about the technologies it uses. This Cookie Policy explains how and why cookies may be stored on and accessed from your device when you use or visit any website or app that posts a link to this Policy. Please read this Cookie Policy carefully before using our Site. This Cookie Policy should be read together with our Data Protection Policy ‘Policy_Personal Data Protection Management’ and our Terms of Use.


When you visit our website fptsoftware.com, we will collect additional website usage data. Cookies are small text files, often including unique identifiers, that are sent by web servers to web browsers, and which may then be sent back to the server each time the browser requests a page from the server.


Cookies are very useful and enable an internet site to recognize you, log when you visit a particular page, provide a secure connection to a website and enhance your user experience by: improving your browsing comfort, and/ or adapting the content of a page to your areas of interest.


We may use information collected from our cookies to identify user behavior and to serve content and offers based on your profile, and for the other purposes described below, to the extent legally permissible in certain jurisdictions. In addition, when you visit our websites, our advertisement partners, whom we have engaged for re-marketing, may introduce cookies. Based on your browsing of our website you may see our advertisements while browsing through our advertisement partner websites and/or their network websites.


Such cookies would allow us to monitor the effectiveness of the advertisements and to make the advertisements more relevant to you.


Information on the Types of Cookies that are used on our Site 

Functional categories of cookies: 

  • Strictly Necessary: Essential for the website to function, such as accessing secure areas. 
  • Functional: Remember choices made by the user, like language or region. 
  • Performance/Analytics: Collect data on how visitors use a website, like which pages are visited most. 
  • Targeting/Advertising: Deliver relevant ads and track ad campaign performance  


 
Cookie Name
Hostname
Domain Cookie Category
Expiry Duration
Expiry Unit
Description
Detail Purpose of Use
 

ARRAffinitySameSite

Strictly Necessary

0

Days

The ARRAffinitySameSite cookie is a cookie used by websites that run on Microsoft Azure to ensure that page requests from visitors are directed to the same server during a browsing session.

ARRAffinity

Strictly Necessary

0

Days

The ARRAffinity cookie is a feature of Azure App Service that allows users to communicate with the same Azure App Service worker instance until their session ends.

sxa_site

Strictly Necessary

0

Days

This cookie 'sxa_site' is used to store the name of the context site and identify the status of user sessions for each page.

__cf_bm

Strictly Necessary

0

Days

The __cf_bm cookie is a cookie necessary to support Cloudflare Bot Management.

shell#lang

Strictly Necessary

0

Days

This cookie shell#lang is used to store the context language of the current site.

__cf_bm

Strictly Necessary

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

_GRECAPTCHA

Strictly Necessary

5

Months

Used by Google reCaptcha for risk analysis.

_cfuvid

Strictly Necessary

0

Days

Used by Cloudflare WAF to distinguish individual users who share the same IP address and apply rate limits.

__cf_bm

Strictly Necessary

0

Days

The __cf_bm cookie is a cookie necessary to support Cloudflare Bot Management.

privacynotification

Strictly Necessary

1

Years

This cookie is used to store the user's interaction status with the privacy or cookie notification banner. It ensures that the notification is displayed appropriately and prevents it from being repeatedly shown once acknowledged by the user.

fso#lang

Strictly Necessary

0

Days

This cookie stores the user's selected language preference to ensure that the website content is displayed in the correct language throughout the browsing session.

_cfuvid

Strictly Necessary

0

Days

Used by Cloudflare WAF to distinguish individual users who share the same IP address and apply rate limits.

__cf_bm

Strictly Necessary

0

Days

The __cf_bm cookie is a cookie necessary to support Cloudflare Bot Management.

__cf_bm

Strictly Necessary

0

Days

The __cf_bm cookie is a cookie necessary to support Cloudflare Bot Management.

_ga

Performance

1

Years

Contains a unique identifier used by Google Analytics to determine that two distinct hits belong to the same user across browsing sessions.

Understanding usage and service improvement: We use cookies to understand the usage of the services provided by this site in order to improve our services and to provide services that better meet the interests and needs of our customers.

_ga_xxxxxxxxxx

Performance

1

Years

Contains a unique identifier used by Google Analytics 4 to determine that two distinct hits belong to the same user across browsing sessions.

_hjSession_xxxxxx

Performance

0

Days

A cookie that holds the current session data. This ensures that subsequent requests within the session window will be attributed to the same Hotjar session.

_clsk

Performance

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

_clck

Performance

1

Years

Persists the Clarity User ID and preferences, unique to that site, on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID.

_hjSessionUser_
xxxxxxx

Performance

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

_gclxxxx

Performance

2

Months

Contains a unique identifier used by Google Analytics 4 to determine that two distinct hits belong to the same user across browsing sessions.

SC_ANALYTICS_
GLOBAL_COOKIE

Performance

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

MUID

Performance

1

Years

Microsoft User Identifier tracking cookie used by Bing Ads. It can be set by embedded microsoft scripts. Widely believed to sync across many different Microsoft domains, allowing user tracking.

SM

Performance

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

pardot

Performance

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

pardot

Performance

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

latest_version

Performance

0

Days

This cookie is used to store the latest version information of website assets or features. It helps manage technical updates, cache control, and user experience consistency across different versions of the website.

__cf_bm

Functional

0

Days

The __cf_bm cookie is a cookie necessary to support Cloudflare Bot Management.

MR

Functional

6

Days

Used by Microsoft Clarity to indicate whether to refresh MUID.

_cfuvid

Functional

0

Days

Used by Cloudflare WAF to distinguish individual users who share the same IP address and apply rate limits.

CLID

Functional

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

_cfuvid

Functional

0

Days

Used by Cloudflare WAF to distinguish individual users who share the same IP address and apply rate limits.

pi_opt_in1029071

Functional

1

Years

This cookie is used by Pardot to store the visitor's consent or opt-in status for marketing tracking. It ensures that marketing and analytics activities are performed in accordance with the user's consent preferences.

pi_opt_in1029071

Functional

1

Years

This cookie is used by Pardot to store the visitor's consent or opt-in status for marketing tracking. It ensures that marketing and analytics activities are performed in accordance with the user's consent preferences.

ANONCHK

Targeting

0

Days

Used to store session ID for a users session to ensure that clicks from adverts on the Bing search engine are verified for reporting purposes and for personalisation.

Distribution of advertisements using cookies: We utilize the advertising services (display advertising/remarketing/
retargeting functions) of ad-serving companies to distribute notices (advertisements) to past visitors to this site when they visit certain pages. In doing so, we use cookies to obtain information on the history of visits to our site.

visitor_id1029071-hash

Targeting

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

visitor_id1029071-hash

Targeting

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

visitor_id#####

Targeting

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

visitor_id#####

Targeting

1

Years

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

__Secure-ROLLOUT_TOKEN

Targeting

5

Months

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

SRM_B

Targeting

1

Years

This cookie is installed by Microsoft Bing. Identifies unique web browsers visiting Microsoft sites.

MUID

Targeting

1

Years

Microsoft User Identifier tracking cookie used by Bing Ads. It can be set by embedded microsoft scripts. Widely believed to sync across many different Microsoft domains, allowing user tracking.

VISITOR_INFO1_LIVE

Targeting

5

Months

Set by YouTube and used for various purposes, including analytical and advertising.

_cfuvid

Targeting

0

Days

Used by Cloudflare WAF to distinguish individual users who share the same IP address and apply rate limits.

YSC

Targeting

0

Days

This cookie is set by YouTube video service on pages with YouTube embedded videos to track views.

VISITOR_PRIVACY
_METADATA

Targeting

5

Months

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

IDE

Targeting

1

Years

Used by Google's DoubleClick to serve targeted advertisements that are relevant to users across the web. Targeted advertisements may be displayed to users based on previous visits to a website. These cookies measure the conversion rate of ads presented to the user.

test_cookie

Targeting

0

Days

Used to check if the user's browser supports cookies.

__Secure-YNID

Targeting

5

Months

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

__Secure-YEC

Targeting

0

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

MR

Targeting

6

Days

This cookie is used for analytics, performance measurement, marketing, or personalization purposes. It is not required for basic site functionality and can be disabled based on user consent.

lpv1029071

Targeting

0

Days

This cookie is set by Pardot to record landing page views and measure visitor interactions with marketing content. It helps track page visits for marketing analytics and campaign performance evaluation.


Links to other websites

This site contains links to other websites, but they are neither FPT Software’s websites nor under control of FPT Software. FPT Software is not responsible for the privacy practices or the content and transactions of such websites. You are required to read carefully the Privacy/Cookie part of those linked websites to assure that you have fully understood the way of personal information collection and sharing before providing your own information. You shall take all responsibility of risk that may incur when using those websites. 


Your rights as a data subject

At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:

  • Right to be informed – you have the right to request information what kind of your personal data are collect, use, processed, for what purpose, from which source, lawful basis of processing 
  • Right of access – you have the right to request a copy of the information that we hold about you. 
  • Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
  • Right to be forgotten/erasure – in certain circumstances you can ask for the data we hold about you to be erased from our records.
  • Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
  • Right of portability – you have the right to have the data we hold about you transferred to another organisation.
  • Right to object – you have the right to object to certain types of processing such as direct marketing.
  • Right to object to automated processing, including profiling – you also have the right to be subject to the legal effects of automated processing or profiling.
  • Right to Object: Individuals can object to the processing of their personal data in certain circumstances.
  • Rights related to Automated Decision Making: Individuals have rights concerning decisions made by automated means that significantly affect them
    According to PDPL91, data subjects has further below rights:
  • The right to consent or refuse, and to withdraw consent for personal data processing;
  • The right to file complaints, denunciations, lawsuits, and claim compensation as prescribed by law;
  • The right to request competent authorities or related entities to implement measures to protect their personal data according to legal regulations 

All the above requests will be forwarded on should there be a third party involved in the processing of your personal data.

FPT Software  accepts the following forms of ID when information on your personal data or data subject rights are requested:

Passport, driving licence, ID card

 
Complaints

If you wish to make a complaint about how your personal data is being processed by FPT Software or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and FPT Software’s data protection representatives Global Data Protection Officer.


Contact details

 
Supervisory authority Vietnam contact details 
Data Protection Officer (DPO), Data Protection Representatives

Contact name:

Ministry of public security

Michael Hering, Global Data Protection Officer

Address line 1:

E2 Duong Dinh Nghe

F-Town Building 3

Address line 2:

Yen Hoa - Cau Giay

Lot E3, Vo Chi Cong Street, High-tech Park, Tang Nhon Phu Ward 

Address line 3:

Ha Noi, Vietnam

HCM City, Vietnam

Telephone:

(+84) 069.2343647 - 069.2341165

+84 902606236


Contact details of other countries supervisory authorities you can get form DPO at any time without any undue delay.

 
Changes on Cookie Statement 

FPT Software reserves the rights to change, modify, add or remove in whole or in part this Privacy Statement at its sole discretion, at any time. Therefore, you are responsible for regularly reviewing this statement. Changes of this Privacy Statements will be posted on this website. These changes will also be effective when they are posted. Your continued use of this statement constitutes your agreement to all such terms.


Contact

If you have any questions about our Cookie Statement or about how to protect your personal information, you can contact the Global Data Protection Officer of FPT Software or every local subsidiary of FPT Software. 
Global Data Protection Officer: Michael Hering, [email protected], +84 902606236,
F-Town Building 3, Lot E3, Vo Chi Cong Street, High-tech Park, Tang Nhon Phu Ward, Ho Chi Minh City, Vietnam

 
2.1. Document Owner and Approval
 

The Data Protection Officer (GDPO) is the owner of this document and is responsible for ensuring that this statement is reviewed in line with the review requirements of the GDPR and Guideline_Personal Data Protection Policy Development_v2.7.

This statement was approved by the COO, board member responsible for data protection, see record of change. 

 
 
3. Appendix
 
3.1. Definition
 

Abbreviations
Description
 

PII, Personal Identifiable Information, Personal Data

Refer to the personal data defined by the EU GDPR (Article 4 (1)), ‘personal data’ means any information relating to an identified  or identifiable natural person (‘data  subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

 


Data Subject

EU GDPR (Article 4 – 1),
Data subject refers to any individual person who can be identified, directly or indirectly.

 

Data Controller

EU GDPR (Article 4 – 7),
Refer to the personal data defined by the EU GDPR (Article 4 (1)), ‘personal data’ means any information relating to an identified  or identifiable natural person (‘data  subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

 

Data Processor

EU GDPR (Article 4 – 8),
Data Processor means a natural or legal person, public authority, agency or anybody which processes data on behalf of the controller.

 

Recipient

EU GDPR (Article 4 – 9),
A natural or legal person, public authority, agency or anybody, to which the personal data are disclosed, whether third party or not.

 

Third Party

EU GDPR (Article 4 – 10),
A natural or legal person, public authority, agency or anybody other than the data subject, controller, processor and persons who under direct authority of controller or processor, are authorized to process personal data

 

DPO/GDPO/ADPO  

Data Protection Officer/Global Data Protection Officer/Assistant Data Protection Officer  

 

DPIA

Data Protection Impacted Assessment

 

PIMS

Personal Information Management System

 

EU

European Union


 
3.2. Related Documents
 


See Guideline_Framework Personal Data Protection Handbook_v1.2
Guideline_Relevant Data Protection Law Regulation Standard_v1.2. (see Data Protection Policy published on our website). 


3.3. Data Protection Law, Vietnam, Overview
 

In Vietnam, personal data protection is governed by the Personal Data Protection Law 2025. Regulations on data protection and privacy can also be found in various legal instruments. The right of privacy and right of reputation, dignity and honour and fundamental principles of such rights are currently provided for in Constitution 2013 (“Constitution”) and Civil Code 2015 (“Civil Code”) as inviolable and protected by law. There is no single data protection law in Vietnam. Regulations on data protection and privacy can be found in various legal instruments. The right of privacy and right of reputation, dignity and honour and fundamental principles of such rights are currently provided for in Constitution 2013 (“Constitution”) and Civil Code 2015 (“Civil Code”) as inviolable and protected by law.


Regarding personal data , the guiding principles on collection, storage, use, process, disclosure or transfer of personal information are specified in the following main laws and documents:

  • Criminal Code No. 100/2015/QH13, passed by the National Assembly on 27 November 2015
  • Law No. 24/2018/QH14 on Cybersecurity, passed by the National Assembly on 12 June 2018 and will expire on July 1st, 2026 (“Cybersecurity Law”); Law No 116/2025/QH15 on Cybersecurity will take effect on July 1, 2026;
  • Law No. 86/2015/QH13 on Network Information Security, passed by the National Assembly on 19 November 2015; as amended by Law No. 35/2018/QH14 dated 20 November 2018, on amendments to some articles concerning planning of 37 Laws (“Network Information Security Law”); will expire on July 1, 2026. Replaced by Law No 116/2025/QH15 on Cybersecurity will take effect on July 1, 2026; 
  • Law 19/2023/QH15 on Protection of Consumers’ Rights, passed by the National Assembly on 20 June 2023 (“CRPL”);
  • Law No. 67/2006/QH11 on Information Technology, passed by the National Assembly on 29 June 2006; as amended by Law No. 21/2017/QH14 dated 14 November 2017 on planning (“IT Law”);
  • Law 20/2023/QH15 on E-transactions, passed by the National Assembly on 22 June 2023 (“E-transactions Law”); 
  • Decree No. 85/2016/ND-CP dated 1 July 2016, on the security of information systems by classification (“Decree 85”);
  • Decree No. 147/2024/NĐ-CP dated 09 November 2024 of the Government, on management, provision and use of Internet services and cyber information; (“Decree 147”); 
  • Decree No. 52/2013/ND-CP dated 16 May 2013 of the Government; as amended by Decree No. 08/2018/ND-CP dated 15 January 2018, on amendments to certain Decrees related to business conditions under state management of the Ministry of Industry and Trade and Decree No. 85/2021/ND-CP dated 25 September 2021 (“Decree 52”);
  • Decree No. 15/2020/ND-CP of the Government dated 3 February 2020 on penalties for administrative violations against regulations on postal services, telecommunications, radio frequencies, information technology and electronic transactions (“Decree 15”);
  • Circular No. 03/2017/TT-BTTTT of the Ministry of Information and Communications dated 24 April 2017 on guidelines for Decree 85 (“Circular 03”);
  • Decree No. 147/2024/NĐ-CP dated 09 November 2024 of the Government, on management, provision and use of Internet services and cyber information; (“Decree 147”);
  • Circular No. 20/2017/TT-BTTTT dated 12 September 2017 of the Ministry of Information and Communications, providing for Regulations on coordinating and responding to information security incidents nationwide (“Circular 20”);
  • Circular No. 48/2025/TT-BKHCN dated 25 December 2025 of the Ministry of Science and Technology of Vietnam, providing for elaborating the management and use of internet resources (“Circular 48”); and
  • Decision No. 05/2017/QD-TTg of the Prime Minister dated 16 March 2017 on emergency response plans to ensure national cyber-information security (“Decision 05”). 

Applicability of the legal documents will depend on the factual context of each case, e.g businesses in the banking and finance, education, healthcare sectors may be subject to specialized data protection regulations, not to mention to regulations on employees’ personal information as provided in Labour Code 2019 (“Labour Code”).


The most important Vietnamese legal documents regulating data protection are the Cybersecurity Law and Network Information Security Law. Cybersecurity laws in other jurisdictions that were inspired by the GDPR of the EU, the Cybersecurity Law of Vietnam shares similarities with China’s Cybersecurity Law enacted in 2017. The law focuses on providing the government with the ability to control the flow of information. The Network Information Security Law enforces data privacy rights for individual data subjects.


A draft Decree detailing a number of articles of the Cybersecurity Law (“Draft Cybersecurity Decree”), notably including implementation guidelines for data localization requirements, together with a draft Decree detailing the order of and procedures for application of a number of cybersecurity assurance measures and a draft Decision of the Prime Minister promulgating a List of information systems important for national security, are being prepared by the Ministry of Public Security (“MPS”) in coordination with other relevant ministries, ministerial-level agencies and bodies.


MPS has drafted a Decree on personal data protection (“Draft PDPD”), which is contemplated to consolidate all data protection laws and regulations into one comprehensive data protection law as well as make significant additions and improvements to the existing regulations. The Draft PDPD was released for public comments in February 2021 and was originally scheduled to take effect by December 2021. The Finalization process consuming much more time than the MPS first anticipated. PDPD was finalized and was coming in force 07/2023. On July 1, 2025, Law 91/2025/QH15 Personal Data Protection Law (PDPL) was published to the national database on legal documents. This follows the draft PDPL being passed by the National Assembly on June 26, 2025. It will come in force 01.01.2026.

On July 1, 2025, Law No. 60/2024/QH15 for the Data Law entered into effect, following its passage by the National Assembly on November 30, 2024.


On December 31, 2025, the Government of Vietnam issued Decree No.356/2025/ND-CP (“Decree 356”), guiding the implementation of the Law on Personal Data Protection 2025 (“PDPL91”). Effective immediately as of January 1, 2026, Decree 356 replaces the previous Decree No. 13/2023/ND-CP.