Using Customer and Employee Data in AI under Vietnamese Law

Updated: 23 September 2026

AI tools can summarise records, retrieve information or support analysis. Where inputs contain personal data, businesses must assess both AI and personal data protection law. A paid account or enterprise edition does not replace these obligations.

Start with the data and intended purpose

Article 30 of the Personal Data Protection Law and Article 10 of Decree No. 356/2025/ND-CP establish protection requirements for AI-related activities. Articles 3, 9 and 19 of the Law still determine principles, consent or qualifying grounds for processing without consent.

For example, data collected to resolve complaints should not automatically be used to train a system serving other customers. Assess the notice scope, processing basis, provider role and new purpose. If only statistics are needed, consider reducing the data or using appropriately processed data. Replacing names with codes does not establish de-identification under Article 2 of the Personal Data Protection Law.

Review contracts and settings together

Clarify whether the provider uses inputs, outputs or feedback for training; retention periods; support access; subcontractors; processing regions; and deletion and export mechanisms. These facts should be supported by service documentation, contracts and actual settings.

Do not infer all processing behaviour from an option such as “turn off history”. For cloud services, also check Article 12 of Decree No. 356 on contracts, permissions and encryption in storage and transit.

Whether an overseas transfer dossier is required

Article 20 of the Personal Data Protection Law covers using platforms outside Vietnam to process personal data collected in Vietnam. Map the flows before reaching a conclusion. Articles 17–18 of Decree No. 356 govern dossiers and exceptions; not all data in an HR tool benefits from the same exception.

A new AI activity may also change the processing impact assessment dossier under Articles 21–22 of the Law. Updates must reflect actual changes and timing rules, rather than merely change a software name in the provider list.

Additional considerations for AI recruitment

Article 25 of the Personal Data Protection Law regulates recruitment and employee management data. AI systems must also be assessed against Decision No. 33/2026/QD-TTg's high-risk list according to function and impact. A job description writing tool and a system influencing candidate selection may receive different classifications.

Identify who reviews output, who can amend or disregard results and how affected individuals can report errors. This organises human responsibility; AI should not be treated as independently accountable for a business's decisions.

Building a control process

Businesses can specify permitted input data, purposes, tools and situations requiring further assessment, while assigning access checks, logging and incident response. These are governance suggestions, not a universal mandatory checklist.

When models, functions or providers change, reassess both data and AI classification. Articles 10–14 of the Artificial Intelligence Law and Decree No. 142/2026/ND-CP determine classification, notification, transparency and risk management duties.

Additional checks for HR records medical files and internal documents

For HR records, check recruitment and employee management purposes and retention limits under Article 25 of the Personal Data Protection Law. For medical records, Articles 10 and 69 of the Law on Medical Examination and Treatment impose separate confidentiality and information-use requirements. Partner documents also require review of usage rights and confidentiality commitments. The same AI function can carry different requirements because its data sources differ.

Anonymisation, encryption and de-identification are not synonymous. If a person can still be identified or the data helps identify them, personal data protection remains relevant. Removing personal information also does not remove intellectual property rights or trade secrets from the remaining material.

What happens to AI data when a user requests deletion

Identify whether data resides in inputs, conversation history, document stores, logs or training datasets. Do not promise immediate complete deletion without understanding technical mechanisms and applicable retention duties. The process must address Article 14 of the Law and Article 5 of Decree No. 356 and involve parties processing the data.

A useful preparation step is to test access or deletion requests using test data before expanding deployment. Results help check consistency between contract terms, individual notices and implementation capabilities. The business responsibility and reference template articles support further development of this process.

Frequently asked questions

Is removing a customer's name enough to upload a file to AI? No. Other content may still identify them. Assess re-identification and the complete processing basis.

Does a provider's no-training commitment establish compliance? It addresses one issue. Purposes, individual rights, security, retention, contracts and transfers still require assessment.

Legal sources

Personal Data Protection Law No. 91/2025/QH15

Decree No. 356/2025/ND-CP implementing personal data protection requirements

Artificial Intelligence Law No. 134/2025/QH15

Decree No. 142/2026/ND-CP implementing the Artificial Intelligence Law

Decision No. 33/2026/QD-TTg on the list of high-risk AI systems

Law on Medical Examination and Treatment No. 15/2023/QH15 — Articles 10 and 69

Law No. 131/2025/QH15 amending the Intellectual Property Law, effective from 1 April 2026

Sources checked through 23 September 2026.

Related articles

Article 02 Vietnam Personal Data Protection Law and Business Responsibilities in 2026

Article 04 Vietnam Personal Data Processing Impact Assessment Requirements

Article 05 Overseas Cloud and CRM Services and Vietnam Data Transfer Filings

Article 16 Vietnam AI Law and System Risk Classification in 2026

Article 21 Vietnam Personal Data Protection Templates and How to Use Them

Similar Blog Posts

Vietnam Personal Data Protection Templates and How to Use Them

Request reference templates for Vietnam personal data protection and understand their scope and the review…

Vietnam and EU Data Protection and AI Laws Compared by Obligation

Compare Vietnam and EU data protection and AI duties, including DPIAs, 72-hour breach rules, territorial…

Vietnam Cloud Service Notification and Data Protection Responsibilities

Explore Vietnam cloud notification rules for domestic and overseas providers and the data protection responsibilities…

Vietnam Data Centre Services Registration and Licensing

Distinguish Vietnam data centre registration from telecommunications licensing, with provincial authority and processing changes under…
Designed by W.O.A.