If your organization processes personal data in India or Vietnam, you're navigating two new regulatory frameworks that launched almost simultaneously. India finalized regulations for the Digital Personal Data Protection Act near the end of 2025, and Vietnam's Personal Data Protection Law became effective on January 1, 2026.
This guide helps you map compliance obligations across both jurisdictions and pinpoint where your current data governance might fall short.
Scope - What This Guide Covers
This guide addresses compliance requirements for organizations that:
- Collect or process personal data of Indian or Vietnamese individuals
- Transfer personal data across borders involving India or Vietnam
- Use cookies or tracking technologies on sites accessible from these jurisdictions
- Operate consent management platforms for users in these markets
It doesn't cover sector-specific regulations (like financial services or healthcare) or employment data rules unless they intersect with general data protection obligations.
Key Concepts and Definitions
Data Fiduciary (India) / Data Controller (Vietnam): The entity that decides the purposes and means of processing. If you determine what data to collect and why, you're the fiduciary or controller.
Data Principal (India) / Data Subject (Vietnam): The individual whose personal data you process.
Cross-Border Transfer: Any movement of personal data outside India or Vietnam, including cloud storage or CRM systems hosted elsewhere.
Consent Standard: Both jurisdictions require consent that is freely given, specific, informed, and unambiguous. Vietnam explicitly requires Prior Consent for certain processing activities. India's regulations specify that consent must be a clear affirmative action, not inferred from silence or pre-ticked boxes.
Sensitive Personal Data: India includes financial data, health records, biometric data, and data revealing sexual orientation. Vietnam's definition covers similar categories but adds genetic data and location data.
Requirements Breakdown
India: Digital Personal Data Protection Act
Consent Mechanism Requirements:
- Request consent in clear, plain language
- Provide separate consent requests for distinct processing purposes
- Allow withdrawal of consent as easily as it was given
- Maintain records showing when, how, and for what purpose consent was obtained
Data Principal Rights:
- Right to access personal data
- Right to correct inaccurate data
- Right to erasure (with exceptions)
- Right to nominate another individual to exercise rights in case of death or incapacity
Cross-Border Transfer Rules: India's regulations require verifying that the destination meets India's adequacy requirements or implementing alternative safeguards.
Breach Notification: Notify the Data Protection Board of India promptly after a breach. The regulations emphasize "without undue delay."
Vietnam: Personal Data Protection Law
Consent Requirements:
- Obtain Prior Consent before processing personal data (with specific exemptions)
- Document the consent mechanism, including timestamp and scope
- Provide a withdrawal mechanism that doesn't require justification
Data Subject Rights:
- Right to access and obtain copies of personal data
- Right to request correction or supplementation
- Right to request deletion or restriction of processing
- Right to data portability
- Right to object to processing for direct marketing
Cross-Border Transfer Framework: Vietnam requires that destination countries provide adequate protection or that you implement standard contractual clauses. Transfers based on explicit consent are allowed, but relying solely on consent for routine transfers can be risky.
Data Protection Impact Assessment: Required for high-risk processing activities, including large-scale processing of sensitive data and systematic monitoring.
Implementation Guidance
Audit Your Current Consent Flows
Map every point where you collect consent from Indian or Vietnamese users. Check if your Consent Management Platform:
- Presents purpose disclosures in the local language
- Separates essential from non-essential processing purposes
- Provides equal prominence to accept and reject options
- Records granular consent signals
Reconfigure Data Transfer Mechanisms
If you transfer data from India or Vietnam to your global infrastructure, document:
- What data categories move across borders
- Which legal mechanism authorizes each transfer
- Where data is stored and who has access
Don't rely on implied consent for cross-border transfers. Both jurisdictions expect explicit authorization for data leaving their territory.
Establish Local Data Subject Request Workflows
Your existing GDPR or CCPA request handling won't automatically satisfy India or Vietnam requirements. Build jurisdiction-specific workflows that:
- Acknowledge requests within the statutory timeframe
- Verify the requester's identity
- Deliver responses in the requested format
- Track rejection reasons if you deny a request
Review Third-Party Processor Agreements
If you share data with vendors, your contracts must specify:
- Processing instructions and limitations
- Security obligations aligned with local standards
- Breach notification timelines
- Sub-processor authorization requirements
Vietnam's law holds controllers liable for processor violations if adequate contractual safeguards aren't implemented.
Common Pitfalls
Assuming GDPR Compliance Equals India/Vietnam Compliance: These frameworks share principles with GDPR but differ on cross-border transfer rules, breach notification timelines, and enforcement mechanisms.
Using Global Consent Notices Without Localization: A consent notice that works in the EU may fail in India if it doesn't address data fiduciary obligations or provide clear withdrawal mechanisms.
Overlooking Sensitive Data Definitions: Vietnam includes location data as sensitive. If you process geolocation, you're handling sensitive personal data under Vietnamese law and must apply heightened protections.
Defaulting to Consent When Another Legal Basis Applies: Both jurisdictions recognize legal bases beyond consent. Relying on consent unnecessarily can create compliance burdens and give users withdrawal rights that could disrupt your service.
Ignoring Data Localization Signals: While neither India nor Vietnam has blanket data localization mandates, sector-specific rules may impose localization for certain data categories. Monitor regulatory developments beyond the core privacy statutes.
Quick Reference Table
| Requirement | India | Vietnam |
|---|---|---|
| Consent Standard | Clear affirmative action, freely given, specific, informed | Prior Consent for most processing; freely given, specific, informed, unambiguous |
| Sensitive Data Categories | Financial, health, biometric, sexual orientation | Genetic, biometric, health, location, financial, ethnic origin, political views |
| Breach Notification | Notify Data Protection Board without undue delay | Notify Ministry of Public Security within 72 hours for high-risk breaches |
| Data Subject Access | Right to access, correction, erasure | Right to access, correction, deletion, portability, objection |
| Cross-Border Transfer | Approved countries or alternative safeguards | Adequacy decision, standard contractual clauses, or explicit consent |
| Data Protection Officer | Not mandated for all organizations | Required for large-scale processing or sensitive data processing |
| Enforcement Authority | Data Protection Board of India | Ministry of Public Security |
| Effective Date | Regulations finalized late 2025 | January 1, 2026 |
Keep this guide accessible for your compliance team's quarterly audits. As enforcement patterns emerge in both jurisdictions, refine these baseline controls based on regulatory guidance and penalty precedents.



