The List of Sensitive Personal Data Effective from January 1, 2026 is a crucial basis for defining information security standards for all organizations and enterprises in Vietnam. Mastering these contents helps enterprises strengthen trust with customers and partners by strictly complying with new regulations. Long Phan Consulting Company analyzes the details below to help clients prepare for this new phase.
The List of Sensitive Personal Data Effective from January 1, 2026
Data about private life
Private Life Data According to Clause 1, Article 4 of Decree 356/2025/ND-CP, private life data classified as sensitive includes:
Data revealing racial or ethnic origin.
Political opinions, religious or philosophical beliefs.
Information about private life, personal secrets, and family secrets.
Health status.
Biometric data and genetic characteristics.
Data revealing sex life or sexual orientation.
Data on crimes and criminal activities collected/stored by law enforcement agencies.
Individual location identified via positioning services.
Usernames and passwords for electronic identity accounts; images of Identity Cards (The Can cuoc), Citizen Identity Cards, or ID cards.
Usernames and passwords for bank accounts; bank card information; transaction history; financial, credit, and insurance information at credit institutions and intermediaries.
Data tracking behavior and usage of telecommunications, social networks, and online services.
Other personal data required by law to be kept confidential.
Health data
Important information reflecting biological status affecting employment and insurance:
Medical records: History, test results, prescriptions, clinical diagnoses.
Physical/Mental status: Assessments of physical capacity, psychological conditions, chronic or infectious diseases.
Genetic information: Genes and chromosomes inherited across generations.
Disability information: Level and type of disability (mobility, hearing, vision…).
Biometric data
Classified as sensitive under Point d, Clause 1, Article 4, Decree 356/2025/ND-CP. Clients using biometric timekeeping or access control must prioritize encryption:
Fingerprints: Common for ID cards and building security.
Face ID: 3D images or facial features for authentication.
Iris/Retina: High-precision scanning.
Voice: Voice samples for recognition.
DNA: Genetic samples for lineage or identity.
Financial and economic data
A primary target for cybercrime requiring international security standards:
Bank account info: Account number, holder name, balance.
Impact Assessment: Mandatory Data Processing Impact Assessment Dossier must be available for inspection.
Accountability: The burden of proof lies with the data controller.
The responsibility of the party collecting personal data when discovering the leakage or loss of sensitive data in financial, banking, and credit information activities.
According to Clause 8, Article 8, Decree 356/2025/ND-CP:
72-Hour Notification: Must notify the specialized agency (Ministry of Public Security) and affected subjects within 72 hours of detection.
Content: Nature of the breach, type of data, estimated consequences, and remedial measures (per Article 28).
Remediation: Immediately apply measures to stop leaks and support customers.
Responsibilities of the data collector under current regulations
Frequently Asked Questions
Below, Long Phan Consulting provides some frequently asked questions related to the list of sensitive personal data from January 1, 2026. We invite interested customers to refer to this information:
What makes consent valid?
It must be verifiable via text, recording, SMS, email, or digital confirmation. Evidence of consent must be stored. (Legal Basis: Clause 1, 2 Article 6, Decree 356/2025/ND-CP).
Is “Default Consent” (pre-ticked boxes) allowed?
No. Setting up default consent or misleading instructions is prohibited. (Legal Basis: Clause 3, Article 6, Decree 356/2025/ND-CP).
Is a special notice required for sensitive data?
Yes. The organization must explicitly notify the subject that the data being requested is “sensitive personal data”. (Legal Basis: Clause 4, Article 6, Decree 356/2025/ND-CP).
How must sensitive data be transferred?
Measures must include physical security of storage/transmission devices, encryption, and anonymization during transfer. (Legal Basis: Clause 2, Article 7, Decree 356/2025/ND-CP).
Who proves consent in a dispute?
The burden of proof lies with the Data Controller or Data Controller and Processor, not the data subject. (Legal Basis: Clause 2, Article 6, Decree 356/2025/ND-CP).
Conclusion
Compliance with the List of Sensitive Personal Data is mandatory and builds sustainable competitive advantage. Long Phan Consulting Company is ready to assist clients in reviewing security processes. Please contact Hotline 1900636389 for professional support.
Facebook
Linkedin
Twitter
Pinterest
Dương Thị Kim Ngân
Jurist Ngan Duong Thi Kim - Partner of Long Phan, Ms. Ngan possesses profound knowledge in business consulting, labor, and contracts. With dedication and creativity, Ms. Ngân has achieved significant success in advising and supporting businesses in critical areas such as legal matters, finance, management, and contracts. She is committed to providing optimal solutions and helping clients succeed in the business environment.