Core Compliance Requirements for A2P Business under Vietnam’s Personal Data Protection Decree

Vietnam’s Decree No.13/2023/NĐ‑CP on Personal Data Protection took effect on 1 July 2023. As the country’s first comprehensive personal data regulation, it has extraterritorial binding force. It governs the processing of mobile phone numbers, call records and other information involved in A2P SMS and voice services, and defines service provider obligations, end-user rights and penalty standards for violations.

The regulation classifies customers’ mobile phone numbers as ordinary personal data. To obtain numbers for business operations, service providers must obtain active and explicit consent from users; user silence cannot be regarded as consent. Users may withdraw consent at any time, and merchants must implement the withdrawal within 72 hours.

A2P operators need to distinguish whether they act as data controllers or data processors. Within 60 days after either type of entity commences user data processing, they must submit a personal data protection impact assessment to the relevant public security authority. Users are entitled to eleven rights including access, deletion and objection to data processing. Service providers must respond to user requests within 72 hours upon receipt.

If it is necessary to transfer Vietnamese residents’ data overseas, enterprises shall complete a cross-border data risk assessment and submit relevant filings. Violations may result in heavy fines, and severe cases may trigger criminal liability. A2P operators shall establish legitimate channels for collecting user consent, clarify data roles, build a rapid request handling mechanism. Enterprises with cross-border data transfer requirements shall complete compliance filings in advance to mitigate penalty risks.