What Must Social Networks and Online Platforms Do to Comply with the Personal Data Protection Law 2025?

For many years, social networking platforms and online media services have developed based on their ability to collect, analyze, and exploit user data. From behavioral data, location, and search history to consumer habits, personal data has become one of the most valuable assets of the digital economy.
However, alongside this development are growing concerns about privacy rights and the risk of user data abuse. The Personal Data Protection Law 2025 has imposed stricter requirements on enterprises providing social networking and online media services, forcing platforms to change how they collect, use, and manage personal data. This not only impacts large technology companies but also directly affects applications, websites, and digital platforms operating in Vietnam. In this article, CDLAF’s lawyers discuss the personal data protection requirements that operators of social networking and online platforms need to pay close attention to.

Source: pexels-visual-tag-mx-1321732-5361087

1. Digital platforms must be transparent about the collection of users’ personal data

One of the crucial requirements for organizations and individuals providing social networking and online media services is to clearly inform users about the types of personal data collected right from the time of installation and use of the service. Simultaneously, enterprises must not collect personal data illegally or beyond the scope agreed upon with the user.

In practice, many platforms often request access to the device’s contacts, location, microphone, camera, or photo library without clearly explaining the reasons and scope of using such data. If users disagree, it means they cannot proceed with further operations to use the platform. This is one of the underlying causes increasing user concerns about personal data being exploited beyond the actual needs of the service.

Examples:

  • A delivery application requests access to the user’s location to determine the delivery address. This may be considered a data collection activity that is necessary for the provision of the service, provided that the user is fully informed.
  • Conversely, a photo editing application requests continuous access to the user’s phone contacts without clearly explaining the purpose of use. In this case, the enterprise may face difficulties in proving the necessity and legality of the data collection activity.

Historically, many enterprises applied the “the more you collect, the better” principle without discussing the necessity of the collection. However, this is no longer appropriate in the context of increasingly tightened Personal Data Protection Law 2025.

2. Requesting images of identity documents for account authentication is prohibited

One of the notable features of the personal data protection framework is the prohibition against organizations and individuals providing social networking and online media services from requiring users to provide images or videos containing all or part of identity documents as a factor for account authentication.

This regulation was promulgated in the context of increasingly common leakages of personal data, especially images of citizen identity cards, passports, and other identification documents. Requesting users to submit photos of identity documents not only increases the risk of data leaks but can also lead to many consequences such as identity theft, unauthorized account opening, or committing other fraudulent acts like establishing companies.

Examples:

  • A social networking platform requires users to submit two-sided photos of citizen identity cards to activate accounts. This authentication method may give rise to significant legal risks if it does not fall under cases permitted by law.
  • A community application requires users to record a video holding an identity document to verify their identity before joining the platform. Enterprises should reassess whether this procedure is necessary and proportionate from the perspective of personal data protection.
  • Meanwhile, using OTP codes sent via phone numbers, email authentication, multi-factor authentication (MFA), or other authentication methods with a lower level of data intrusion could be priority solutions for consideration.

From legal regulations to practical perspectives, we see that before deploying any authentication mechanism, enterprises need to answer three crucial questions: Is the collection of this data truly necessary? Is there a less intrusive alternative solution? And has the enterprise established sufficient measures to protect the data after collection?. In a context where user trust is increasingly tied to how enterprises treat personal data, the principle of “minimal collection while still ensuring authentication objectives” should be viewed as a priority orientation in designing digital products and services.

3. Users must have the right to reject cookies and online tracking activities

According to PD law regulations, organizations and individuals providing social networking and online media services must provide users with the option to refuse or withdraw consent to the use of cookies and similar tracking technologies, and simultaneously must provide a “do not track” option or only conduct tracking activities with the user’s consent.

This is considered one of the most significant changes for digital platforms and enterprises operating websites and mobile applications in Vietnam. For many years, cookies and tracking technologies have become popular tools for analyzing user behavior, personalizing content, and deploying targeted advertising. However, users are often not provided with adequate information or control mechanisms regarding this data collection activity.

4. Eavesdropping, recording calls, or reading messages without user consent is prohibited

The law explicitly stipulates that organizations and individuals providing social networking and online media services must not wiretap, eavesdrop, record calls, or read text messages of users without the consent of the personal data subject, unless otherwise prescribed by law.

This regulation demonstrates strong protection for privacy in the electronic communications of users. Although, in practice, it will be difficult for management agencies and even users to verify whether the platform is truly not recording or eavesdropping. However, with recent policies of the Government and management agencies on cybersecurity, we believe that platform-owning enterprises will need to review their platforms to ensure compliance, while also preparing matters for accountability purposes with management agencies upon inspection.

5. Privacy policies must be transparent and empower users with data control

Organizations and individuals providing social networking and online media services are responsible for publicly disclosing privacy policies, clearly explaining how personal data is collected, used, and shared. Simultaneously, enterprises must provide users with appropriate mechanisms to exercise their rights over their personal data.

Specifically, enterprises need to:

  • Publicly disclose privacy policies and clearly explain how personal data is collected, used, stored, and shared;
  • Provide mechanisms for users to access, rectify, or delete their personal data;
  • Allow users to configure privacy settings suitable for their usage needs;
  • Establish mechanisms to receive and process reports and complaints related to privacy rights and data security;
  • Implement measures to protect the personal data of Vietnamese citizens in the event of cross-border data transfers;
  • Develop procedures to handle personal data breaches rapidly and efficiently.

This regulation indicates that a privacy policy is no longer merely a legal document posted on a website to “cope” with compliance requirements. Instead, this must be a tool to help users understand how their data is being processed and empower them with control over their own personal data. Therefore, enterprises need to change their approach to privacy policies. Instead of viewing this as a formalistic document, enterprises should consider it a public commitment to users regarding personal data management. This requires close coordination among the legal, information technology, product, and customer care departments to ensure that what is announced in the privacy policy can be implemented in practice.

6. Enterprises must establish personal data protection and incident response mechanisms

Besides publicly disclosing privacy policies, organizations and individuals providing social networking and online media services also bear the responsibility of establishing personal data protection measures during service operations, including handling incidents related to privacy rights and information security.

Accordingly, enterprises need to:

  • Protect the personal data of Vietnamese citizens, including cases where data is transferred outside the territory of Vietnam;
  • Establish mechanisms for users to report acts infringing upon privacy rights or personal data breaches;
  • Develop procedures to receive, assess, and handle incidents related to personal data rapidly and efficiently;
  • Implement appropriate technical and administrative measures to mitigate the risks of loss, unauthorized access, or abuse of personal data.

This demonstrates that an enterprise’s responsibility does not end once personal data has been collected but extends throughout the entire personal data processing lifecycle. When an incident occurs, the ability to detect it early and respond promptly will determine the extent of the impact on users as well as the enterprise’s reputation.

For enterprises providing social networking and online media services, personal data is not only a vital resource for product development and enhancing user experience but also a legal responsibility that must be managed stringently. From collecting data, using cookies, deploying user tracking mechanisms, and authenticating accounts, to establishing privacy policies and responding to data incidents, every activity needs to be reviewed from the perspective of compliance with Personal Data Protection Law 2025.

From consulting practice, CDLAF observes that many technology enterprises today are still focusing on product development speed but have not adequately invested in designing and operating personal data management systems. Meanwhile, user trust increasingly depends on the degree of transparency and accountability demonstrated by enterprises in processing personal data.

Time of writing: June 09, 2026

The article contains general information which is of reference value. In case you want to receive legal opinions on issues you need clarification on, please get in touch with our Lawyer  at  info@cdlaf.vn

Why choose CDLAF’s service?

  • We provide effective and comprehensive legal solutions that help you save money and maintain compliance in your business;
  • We continue to monitor your legal matters even after the service is completed and update you when there are any changes in the Vietnamese legal system;
  • Our system of forms and processes related to labor and personnel is continuously built and updated and will be provided as soon as the customer requests it;
  • As a Vietnamese law firm, we have a thorough understanding of Vietnam’s legal regulations, and grasp the psychology of employees, employers, and working methods at competent authorities;
  • CDLAF’s team of lawyers has many years of experience in the field of labor and enterprises, as well as human resources and financial advisory.
  • Strict information security procedures throughout the service performance and even after the service is completed.

You can refer for more information:

    SEND CONSULTATION REQUEST