
PERSONAL DATA PROTECTION IN VIETNAM’S PUBLIC ADMINISTRATION: A COMPARATIVE ANALYSIS WITH THE EU GENERAL DATA PROTECTION REGULATION
1. Introduction. – 2. Methods. – 3. Results and Discussion. – 3.1. Normative Architecture for the Protection of Personal Data in the Public Sector. – 3.2. The Architecture of Institutional Accountability and the Oversight Frameworks for the Governance of Data Protection in the Public Sector. – 3.3. Administrative Implementation and Compliance in Public-Sector Data Protection Frameworks. – 3.4. Analytical Framework for Legal Integration and Advancing Public Data Governance Systems. – 4. Conclusion.
Abstract
Background: The expansion of data-driven governance has intensified personal data protection within public administration. Although contemporary data protection regimes share common principles, their operation in the public sector remains uneven. This study examines how the General Data Protection Regulation (GDPR) and Vietnam’s Law No. 91/2025/QH15 regulate personal-data processing by public authorities and what their differences imply for institutional accountability and individual rights.
Method: The study assesses normative architecture, institutional responsibilities, and compliance frameworks in the two legal systems. It combines systematic comparative legal analysis of primary legal instruments with thematic analysis of secondary sources, allowing for both structural comparison and contextual interpretation across jurisdictions. The doctrinal analysis identifies formal legal requirements, while observations concerning implementation are derived from secondary literature and are not presented as original empirical findings.
Results and Conclusions: The findings demonstrate that robust legal frameworks do not ensure effective protection. The two systems show partial convergence in general data-protection principles but significant differences in public-sector processing, impact assessment, internal compliance functions, supervisory independence, and enforcement. Differences in administrative capacity, organizational culture, oversight arrangements, and digital governance strategies identified in the secondary literature may influence compliance. Accordingly, formal convergence should not be interpreted as institutional or functional equivalence. The research concludes that meaningful personal data protection in public administration depends on the alignment of law, institutions, and governance practices. Context-sensitive harmonization, supported by effective oversight and administrative capacity, is essential to safeguarding individual rights and enhancing trust in data-driven public governance.
About Authors
Nguyen Thi Thuy
Faculty of Administrative and State Law, Hanoi Law University, Vietnam
https://orcid.org/0009-0003-2759-0960
Co-author, responsible for Conceptualization; Data curation; Software; Writing – original draft.
Tran Kim Lieu*
Law Clinic, Hanoi Law University, Vietnam
https://orcid.org/0009-0008-7896-1369
Corresponding author, Data curation; Formal Analysis; Methodology; Project administration; Resources; Supervision; Writing – review & editing.
Vu Van Tuan
Faculty of Legal Foreign Languages, Hanoi Law University, Vietnam
https://orcid.org/0000-0002-3066-7338
Co-author, responsible for Validation; Visualization; Writing – review & editing.
Competing interests: No competing interests were disclosed.
Disclaimer: The authors declare that the opinion and views expressed in this manuscript are free of any impact of any organizations.
Funding Statement
The authors received no specific grant or external funding for the research and publication of this article. Consequently, the Article Processing Charge (APC) was partially waived (50%) by the publisher in accordance with the AJEE Charges Policy for eligible countries (as per the IMF classification at the time of submission). The remaining balance was covered by the authors.
Rights and Permissions
Copyright: © 2026 Nguyen Thi Thuy, Tran Kim Lieu, Vu Van Tuan. This is an open access article distributed under the terms of the Creative Commons Attribution License, (CC BY 4.0), which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
Editors
Managing Editor – Mag. Yuliia Hartman. Ukrainian Editor – Lilia Hartman.
References
1. Allam Z and Dhunny ZA, ‘On Big Data, Artificial Intelligence and Smart Cities’ (2019) 89 Cities 80 <https://doi.org/10.1016/j.cities.2019.01.032> accessed 20 April 2026
2. Anh DK, Phong PX and Quang PD, ‘Enhancing the Responsibilities of Data Controllers in Vietnam: Insights from the European General Data Protection Regulation’ (2024) 40(1) VNU Journal of Science: Legal Studies 90 <https://doi.org/10.25073/2588-1167/vnuls.4610> accessed 20 April 2026
3. Bach TNN and Nguyen NPH, ‘Addressing the Challenges of Data Privacy Protection Law in Vietnam’ (2023) 39(1) VNU Journal of Science: Legal Studies 30 <https://doi.org/10.25073/2588-1167/vnuls.4413> accessed 20 April 2026
4. Bojang MBS, ‘Challenges and Successes of E-Government Development in Developing Countries: A Theoretical Review of the Literature’ (2019) 3(4) International Journal of Research and Innovation in Social Science 410 <https://rsisinternational.org/virtual-library/papers/challenges-and-successes-of-e-government-development-in-developing-countries-a-theoretical-review-of-the-literature/> accessed 20 April 2026
5. Borgesius FJZ and Steenbruggen W, ‘The Right to Communications Confidentiality in Europe: Protecting Privacy, Freedom of Expression, and Trust’ (arXiv, 9 October 2025) arXiv:2510.08247 [cs.CY] <https://doi.org/10.48550/arXiv.2510.08247> accessed 20 April 2026
6. Braun V and Clarke V, Thematic Analysis: A Practical Guide (SAGE 2021)
7. Buruiana A, ‘Personal Data Protection in the Digitalization Process of the Public Administration’ (2024) 11(2) European Journal of Law and Public Administration 15 <https://doi.org/10.18662/eljpa/11.2/227> accessed 20 April 2026
8. Chohan SR and Hu G, ‘Strengthening Digital Inclusion Through E-Government: Cohesive ICT Training Programs to Intensify Digital Competency’ (2022) 28(1) Information Technology for Development 16 <https://doi.org/10.1080/02681102.2020.1841713> accessed 20 April 2026
9. Do HQ and Bui NL, ‘Discussing Personal Data Protection During Arbitration Proceedings and Lessons for Vietnam’ (2024) 9(6) European Journal of Social Sciences Studies 75 <http://dx.doi.org/10.46827/ejsss.v9i6.1691> accessed 20 April 2026
10. Esposito M, Akbar Y and Campbell FX, Digitalization in Emerging Economies (CUP 2025)
11. González Pascual M, ‘Public Administrations and Data Protection’ in Sommermann KP, Krzywoń A and Fraenkel-Haeberle C (eds), The Civil Service in Europe: A Research Companion (Routledge 2025) 649 <http://dx.doi.org/10.4324/9781003458333-40> accessed 20 April 2026
12. Guamán DS and others, ‘Automated GDPR Compliance Assessment for Cross-Border Personal Data Transfers in Android Applications’ (2023) 130 Computers & Security 103262 <https://doi.org/10.1016/j.cose.2023.103262> accessed 20 April 2026
13. Ha HT and Vu TV, ‘Potential Conflicts in Personal Data Protection under Current Legislation in Vietnam Compared with European General Data Protection Regulation’ (2024) 7(3) Access to Justice in Eastern Europe 505 <https://doi.org/10.33327/ajee-18-7.3-a000304> accessed 20 April 2026
14. Hoofnagle CJ, van der Sloot B and Borgesius FZ, ‘The European Union General Data Protection Regulation: What It Is and What It Means’ (2019) 28(1) Information & Communications Technology Law 65 <https://doi.org/10.1080/13600834.2019.1573501> accessed 20 April 2026
15. Hu G and others, ‘The Influence of Public Engaging Intention on Value Co-Creation of E-Government Services’ (2019) 7 IEEE Access 111145 <https://doi.org/10.1109/ACCESS.2019.2934138> accessed 20 April 2026
16. Huynh TT, ‘Everyone is Safe Now: Constructing the Meaning of Data Privacy Regulation in Vietnam’ (2024) 11(4) Asian Journal of Law and Society 530 <https://doi.org/10.1017/als.2024.36> accessed 20 April 2026
17. Iriye R, ‘The European Union General Data Protection Regulation’ (Stimson Center, 24 September 2024) <https://www.stimson.org/2024/the-european-union-general-data-protection-regulation/> accessed 20 April 2026
18. Jagannadh ML and Sumitra S, ‘Comparative Analysis of Data Protection and Privacy Laws’ (2025) 23(s6) Lex Localis – Journal of Local Self-Government 8565 <https://doi.org/10.52152/51h4tr43> accessed 20 April 2026
19. Janssen M and others, ‘Trustworthiness of Digital Government Services: Deriving a Comprehensive Theory Through Interpretive Structural Modelling’ (2018) 20(5) Public Management Review 647 <https://doi.org/10.1080/14719037.2017.1305689> accessed 20 April 2026
20. Joshi PR and Islam S, ‘E-Government Maturity Model for Sustainable E-Government Services from the Perspective of Developing Countries’ (2018) 10(6) Sustainability 1882 <https://doi.org/10.3390/su10061882> accessed 20 April 2026
21. Jurczuk M and Suprunowicz M, ‘Consent in Data Privacy: A General Comparison of GDPR and HIPAA’ (2024) 16 Przegląd Prawniczy Uniwersytetu Im Adama Mickiewicza 173 <https://doi.org/10.14746/ppuam.2024.16.07> accessed 20 April 2026
22. Kawintiranon K and Liu Y, ‘Towards Automatic Comparison of Data Privacy Documents: A Preliminary Experiment on GDPR-Like Laws’ (arXiv, 1 May 2021) arXiv:2105.10117 [cs.CL] <https://doi.org/10.48550/arXiv.2105.10117> accessed 20 April 2026
23. Kim SK, Park MJ and Rho JJ, ‘Does Public Service Delivery Through New Channels Promote Citizen Trust in Government? The Case of Smart Devices’ (2019) 25(3) Information Technology for Development 604 <https://doi.org/10.1080/02681102.2017.1412291> accessed 20 April 2026
24. Kuner C, ‘Protecting EU Data Outside EU Borders under the GDPR’ (2023) 60(1) Common Market Law Review 77 <https://doi.org/10.54648/cola2023004> accessed 20 April 2026
25. Le CTQ, Tran VD and Nguyen DPT, ‘Global Norms and Regional Innovation: GDPR, Evolution of Data Protection in ASEAN and the Legal Trajectory of AI in Vietnam’ (2025) 15(3) TalTech Journal of European Studies 250 <https://doi.org/10.2478/bjes-2025-0039> accessed 20 April 2026
26. Le VC, Nguyen XQ and Ngo KT, ‘Processing of Children’s Personal Data: A Comparative Study of the EU Legal Framework and Vietnamese Law’ (2025) 15(2) TalTech Journal of European Studies 56 <https://doi.org/10.2478/bjes-2025-0020> accessed 20 April 2026
27. Ma L and Zheng Y, ‘National E-Government Performance and Citizen Satisfaction: A Multilevel Analysis Across European Countries’ (2019) 85(3) International Review of Administrative Sciences 506 <https://doi.org/10.1177/0020852317703691> accessed 20 April 2026
28. Nam GD and Khoi TD, ‘More than Just Privacy: Latent Policies for the Codification of Vietnamese Personal Data Protection Law’ (2025) 15(3) International Data Privacy Law 268 <https://doi.org/10.1093/idpl/ipaf013> accessed 20 April 2026
29. Nannini L and others, ‘Beyond Phase-In: Assessing Impacts on Disinformation of the EU Digital Services Act’ (2024) 5(2) AI and Ethics 1241 <https://doi.org/10.1007/s43681-024-00467-w> accessed 20 April 2026
30. Nguyen HBH, ‘Addressing Fragmentation in Vietnam’s Data Protection Laws: Recommendations for a Unified Legal Framework’ (2024) 11(2) Vietnamese Journal of Legal Sciences 14 <https://doi.org/10.2478/vjls-2024-0008> accessed 20 April 2026
31. Pencheva I, Esteve M and Mikhaylov SJ, ‘Big Data and AI – A Transformational Shift for Government: So, What Next for Research?’ (2020) 35(1) Public Policy and Administration 24 <https://doi.org/10.1177/0952076718780537> accessed 20 April 2026
32. Rosenberg D, ‘Use of E-Government Services in a Deeply Divided Society: A Test and an Extension of the Social Inequality Hypotheses’ (2019) 21(2) New Media & Society 464 <https://doi.org/10.1177/1461444818799632> accessed 20 April 2026
33. Ryngaert C and Taylor M, ‘The GDPR as Global Data Protection Regulation?’ (2020) 114 American Journal of International Law 5 <https://doi.org/10.1017/aju.2019.80> accessed 20 April 2026
34. Samuel G, An Introduction to Comparative Law Theory and Method (Bloomsbury Publishing 2014)
35. Sirur S, Nurse JRC and Webb H, ‘Are We There Yet? Understanding the Challenges Faced in Complying with the General Data Protection Regulation (GDPR)’ (arXiv, 22 August 2018) arXiv:1808.07338 [cs.CY] <https://doi.org/10.48550/arXiv.1808.07338> accessed 20 April 2026
36. Streinz T, ‘The Evolution of European Data Law’ in Craig P and de Búrca G (eds), The Evolution of EU Law (3rd edn, OUP 2021) 902 <https://doi.org/10.1093/oso/9780192846556.003.0029> accessed 20 April 2026
37. Thai TTD, Nguyen VD and Nguyen VL, ‘A Comparative Study of Cross-Border Data Transfer Regulations in Vietnam and Singapore Ensuring the Protection of Privacy’ (2025) 26(2) Asia-Pacific Journal on Human Rights and the Law 81 <https://doi.org/10.1163/15718158-26020001> accessed 20 April 2026
38. Tikkinen-Piri C, Rohunen A and Markkula J, ‘EU General Data Protection Regulation: Changes and Implications for Personal Data Collecting Companies’ (2017) 34(1) Computer Law & Security Review 134 <https://doi.org/10.1016/j.clsr.2017.05.015> accessed 20 April 2026
39. To TL, ‘Some Legal Aspects of Personal Data Protection in the World: Experience for Vietnam’ (2024) 10(1) Cogent Social Sciences 2414872 <https://doi.org/10.1080/23311886.2024.2414872> accessed 20 April 2026
40. Tong TPT, ‘Laws on Personal Data Protection in Vietnam Today’ (2025) 14(1) International Journal of Engineering Inventions 47 <https://www.ijeijournal.com/v14-i1.html> accessed 20 April 2026
41. Voigt P and von Dem Bussche A, ‘Practical Implementation of the Requirements under the GDPR’ in Voigt P and von Dem Bussche A, The EU General Data Protection Regulation (GDPR): A Practical Guide (Springer 2017) 245 <https://doi.org/10.1007/978-3-319-57959-7_10> accessed 20 April 2026
42. Ziemba EW, ‘The Contribution of ICT Adoption to the Sustainable Information Society’ (2019) 59(2) Journal of Computer Information Systems 116 <https://doi.org/10.1080/08874417.2017.1312635> accessed 20 April 2026
Reviews for article
Add a Review
АНОТАЦІЯ УКРАЇНСЬКОЮ МОВОЮ
Дослідницька стаття
ЗАХИСТ ПЕРСОНАЛЬНИХ ДАНИХ У ПУБЛІЧНІЙ АДМІНІСТРАЦІЇ В’ЄТНАМУ: ПОРІВНЯЛЬНИЙ АНАЛІЗ ІЗ ЗАГАЛЬНИМ РЕГЛАМЕНТОМ ЄС ПРО ЗАХИСТ ДАНИХ
Нгуєн Тхі Тхуй, Чан Кім Льєу*, Ву Ван Туан
АНОТАЦІЯ
Передумови. Розширення масштабів врядування на основі даних актуалізувало проблему захисту персональних даних у сфері публічної адміністрації. Хоча сучасні режими захисту даних ґрунтуються на спільних засадах, їх функціонування в публічному секторі залишається неоднорідним. У цьому дослідженні проаналізовано, як GDPR та Закон В’єтнаму № 91/2025/QH15 регулюють обробку персональних даних органами публічної влади, а також які наслідки мають виявлені між ними розбіжності для інституційної підзвітності та прав фізичних осіб.
Методи. У межах дослідження оцінено нормативну архітектуру, інституційну відповідальність і механізми забезпечення відповідності (комплаєнсу) у двох правових системах. Поєднання систематичного порівняльно-правового аналізу первинних нормативно-правових актів із тематичним аналізом вторинних джерел уможливило як структурне зіставлення, так і контекстуальне тлумачення правових реалій обох юрисдикцій. Доктринальний аналіз виявляє формальні юридичні вимоги, тоді як висновки щодо правозастосування ґрунтуються на опрацюванні вторинних джерел і не позиціонуються як первинні емпіричні результати.
Результати та висновки. Результати засвідчують, що наявність розвиненої правової бази сама по собі не гарантує ефективного захисту. Обидві системи демонструють часткову конвергенцію загальних засад захисту даних, утім істотно різняться щодо обробки даних у публічному секторі, оцінки впливу, внутрішніх функцій комплаєнсу, незалежності наглядових органів і механізмів примусового виконання правових вимог. Відмінності в адміністративній спроможності, організаційній культурі, системі нагляду та стратегіях цифрового врядування, виявлені у вторинній літературі, здатні впливати на рівень дотримання встановлених вимог. Відтак, формальну конвергенцію не слід ототожнювати з інституційною або функціональною еквівалентністю. Доведено, що дієвий захист персональних даних у публічній адміністрації залежить від узгодженості законодавства, інституцій та управлінських практик. Контекстуально адаптована гармонізація, підкріплена дієвим наглядом і належною адміністративною спроможністю, є критично важливою для гарантування прав людини та підвищення довіри до публічного врядування, заснованого на даних.
Ключові слова: адміністративне право, управління даними, цифрове врядування, гармонізація законодавства, захист персональних даних.
Publication history
-
DETAILS FOR PUBLICATION
Date of submission: 18 Jun 2026
Date of acceptance: 03 Aug 2026
Online First Publication: 26 Sep 2026
Рublication: Nov 2026
Whether the manuscript was fast tracked? - No
Number of reviewer report submitted in first round: 2 reports
Number of revision rounds: 1 round with minor revisions
Technical tools were used in the editorial process
Plagiarism checks - Turnitin from iThenticate
https://www.turnitin.com/products/ithenticate/
Scholastica for Peer Review
https://scholasticahq.com/law-reviews
Paperpal for Academic Editing & Proofreading
https://paperpal.com/
AI DISCLOSURE STATEMENT
The authors acknowledge the use of Grammarly to improve language clarity and grammar.
While the authors acknowledge the usage of AI, they maintain that they are the sole authors
of this article and take full responsibility for the content therein, as outlined in COPE
recommendations.
How to cite it?
-
Nguyen TT, Lieu TK and Vu VT, ‘Personal Data Protection in Vietnam’s Public Administration: A Comparative Analysis with the EU General Data Protection Regulation’ (2026) 9(4) Access to Justice in Eastern Europe <https://doi.org/10.33327/AJEE-18-9.4-a0002011>