Skip to content
Blog

The Data Law and PDPL: telling them apart to comply correctly

Nguyễn Minh ĐứcNguyễn Minh Đức · Data protection & compliance specialist··7 min read
The Data Law and PDPL: telling them apart to comply correctly

Photo: Ilya Semenov / Unsplash

Two laws are often confused: the Data Law (60/2024/QH15) and the Personal Data Protection Law (PDPL, 91/2025/QH15). The names are close, both speak of "data", and both arrived within a short window, so it is easy to treat them as one. But they govern two different scopes, for two different policy reasons, and they place two different sets of obligations on a business. Knowing where the line runs helps you comply on point, avoid doing work that was never your duty, and, more importantly, avoid missing the duties that genuinely do apply.

This piece separates the two laws layer by layer: what each governs, where they overlap, what a business must do for each, and a quick way to answer "which law applies to me".

What the Data Law (60/2024) governs

The Data Law took effect on 1 July 2025 and is the first dedicated law framing data in general. "Data in general" here means any digital data an organization creates, collects, stores or exploits, regardless of whether it is tied to a specific person. Operational figures, sensor data, geographic data, aggregate financial data, and domain databases all fall within its view.

The focus of the Data Law is governance and data sovereignty at the national and organizational level. Its content can be grouped into a few themes:

Building and governing digital data. The law sets principles for creating, updating, connecting and sharing data, alongside establishing databases and the National Data Center as shared infrastructure.

Exploiting and sharing data. It governs how data is shared between agencies and organizations, and the conditions under which data becomes a resource to be used rather than sitting idle in separate silos.

Controlling core and important data going abroad. For categories deemed important to security or the economy, moving them outside the territory is subject to stricter conditions rather than treated as an ordinary technical operation.

In short, the Data Law answers "how is the nation's and the organization's data governed, shared, and protected as a matter of sovereignty". The individual, as a holder of privacy rights, is not the center of this law.

What PDPL (91/2025) governs

The Personal Data Protection Law took effect on 1 January 2026, together with Decree 356/2025/ND-CP guiding its implementation. Before it, the foundation for this field was Decree 13/2023/ND-CP; PDPL raises personal-data protection principles from decree level to statute level and adds many detailed obligations.

PDPL's scope is narrower but deeper: it governs only personal data, meaning information tied to an identified or identifiable person. The core difference from the Data Law is that here the individual, as the data subject, is precisely what must be protected. Its characteristic obligations include:

Data-subject rights. Individuals may know about, access, correct, withdraw consent, restrict, and request deletion of their data, with deadlines by which the processor must respond.

Consent as the basis for processing. Collecting and using personal data must rest on valid, verifiable consent, which is especially strict for sensitive data.

Impact assessment and cross-border transfer of personal data. The processor must produce a data processing impact assessment record, and a separate record when transferring personal data outside the territory.

Data protection personnel, breach notification, penalties. The law requires a data protection function or officer, a process for notifying incidents, and sets penalties for violations.

In short, PDPL answers "how is each individual's privacy protected when an organization processes their data".

A quick side-by-side

| Criterion | Data Law 60/2024 | PDPL 91/2025 (+ Decree 356/2025) |

| --- | --- | --- |

| Effective | 1 July 2025 | 1 January 2026 |

| Scope | All digital data in general | Personal data only |

| What is protected | Sovereignty and the data resource of the nation and organization | The individual, as a data subject |

| Central idea | Governance, sharing, data sovereignty | Privacy and consent |

| Characteristic duties | Data governance, connection and sharing, control of core and important data going abroad | Consent, data-subject rights, impact assessment, cross-border transfer of personal data, data protection personnel, breach notification |

| Prior legal basis | The first dedicated law on data | Inherits and upgrades Decree 13/2023 |

The table is only for quick orientation. In reality a single processing activity can touch both columns at once, which is why the overlap section matters.

Where the two laws overlap

The most confusing point is that personal data is also a kind of data. So when an organization processes personal data, that activity sits inside the large set of "data in general" covered by the Data Law, and at the same time inside the narrow set of "personal data" governed by PDPL. This is not a contradiction but two nested circles: PDPL is the smaller circle inside, with specialized and stricter rules for the portion of data tied to people.

The practical consequences:

  • A business is almost always subject to both at once. You have operational data within the Data Law's scope, and customer and employee data within PDPL's scope.
  • When both laws touch the same situation, the safe approach is to apply the stricter requirement. For personal data, PDPL's specialized duties are usually the floor you must reach.
  • Transferring data abroad is where the two laws most clearly overlap: transferring core and important data falls under the Data Law, while transferring personal data falls under PDPL. The same outbound data flow can trigger obligations under both.

What a business must do for each

Because the scopes differ, the task lists differ too, even where they overlap.

For the Data Law. Know which categories of data you hold and which could be considered core or important. Review outbound data flows, including the use of offshore platforms to process data. Prepare to connect and share data under the general governance framework when required.

For PDPL. Map your personal data, standardize how you collect and store consent evidence, appoint data protection personnel, produce impact assessment records and cross-border transfer records, and build processes for responding to data-subject requests and for breach notification. The detailed task list by workstream, with owners and the evidence to keep, is laid out in the PDPL compliance checklist for businesses.

What both share is that you must know where your data sits and who can touch it. That is also why both laws reinforce the case for keeping data on controllable infrastructure, a theme covered more fully in why keeping data in-country is becoming the norm.

Which law applies to me

You can answer quickly with a few questions:

  • Do you process digital data to run your organization? Almost certainly yes, so the Data Law is already in your field of view on the governance side and, if it applies, on moving core and important data abroad.
  • Within that data, is any of it tied to a specific person: a name, a phone number, an employee file, a customer's transaction history? If so, that portion falls under PDPL, and you must perform PDPL's specialized obligations for it.
  • Does any data flow leave Vietnamese territory, even indirectly through a foreign platform? If so, check it from both angles: is it core and important data under the Data Law, and is it personal data under PDPL.

The pragmatic conclusion for most businesses: you are subject to both. The right question is not "which law" but "for each set of data, which obligation am I standing under". Answer that and compliance gains a focus, instead of being spread thin while still leaving gaps.

Takeaway

The Data Law and PDPL neither replace nor contradict each other. The Data Law handles data in general with a focus on governance and sovereignty; PDPL handles personal data specifically with a focus on the individual's rights. Personal data sits inside both, so an organization usually has to comply with both at once, and at the overlap you apply the stricter standard. The cleanest way forward is to start from a clear data map, mark what is personal data and what leaves the country, then attach each part to its matching obligation.

Both laws lean toward the same technical principle: keep data where you control it and can prove that control. Tetra eOffice runs on-premise, keeping data and access logs inside your own systems, which makes the evidence easier to produce when you reconcile against either law. If you need to review your current state and build a roadmap, book a consultation.

Note: this article is for reference only and is not a substitute for legal advice; businesses should check the current legal texts and consult legal experts for their specific situation.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist