News & library

PERSONAL DATA AND COPYRIGHT UNDER VIETNAM’S LAW ON ARTIFICIAL INTELLIGENCE

23/09/2026

Than Trong Ly – Partner

On 1 March 2026 the Law on Artificial Intelligence No. 134/2025/QH15 (the “AI Law”) came into force. Together with Decree 142/2026/ND-CP implementing it and Decision 33/2026/QD-TTg issuing the list of high-risk artificial intelligence systems (“AI Systems”), these instruments form a dedicated legal framework for artificial intelligence in Vietnam.

Neither the AI Law nor its implementing instruments lays down standards of its own for personal data or for copyright. Yet through cross-referencing and related provisions the Law has a considerable effect on both regimes. This article examines that relationship and some of the ways in which the AI framework bears on the law of personal data protection and of intellectual property, namely: (i) obligations concerning the provenance of the data used to train AI models; (ii) the conditions for using copyright-protected text and data to train AI; and (iii) the conditions under which AI-assisted output attracts copyright protection.

A breach of sector legislation may constitute a breach of the AI Law

Article 7 of the AI Law prohibits the collection, processing or use of data to develop, train, test or operate an AI System in breach of the law on data, personal data protection, intellectual property and cybersecurity.

This is a deliberate piece of legislative technique. Article 7 does not itself define the prohibited conduct but refers instead to the rules of the relevant sector legislation, so that a breach of those rules, when it occurs in the course of collecting, processing or using data for an AI System, simultaneously constitutes conduct prohibited under the AI Law. The consequence is that, alongside the sanctions available under the sector legislation, a business also faces the regulatory measures particular to the AI framework, under which the competent authority may require the risk level of the AI System to be reclassified and, in serious cases, order its operation to be suspended.

Sanctions under sector legislation usually take the form of a fine commensurate with the breach, whereas measures under the AI Law are directed at the operating AI System itself and affect the ability to continue exploiting it. In other words, an error in the preparation or exploitation of data, ordinarily treated as a technical matter, may turn into a risk of business interruption.

Common scenarios of personal data breaches

In practice, personal data breaches in the training of AI Systems tend to arise from operational habit rather than from intent. In the first scenario, a business uses its existing store of customer data, comprising transaction history, service usage behaviour or exchanges with the customer care team, to train an internal model or AI System without de-identification, encryption or the security measures required. As a matter of law, AI training may constitute a new purpose falling outside the scope of the original consent, which typically covered only service provision and marketing. Vietnamese law, moreover, does not permit reliance on legitimate interests as broadly as European Union law does. On the contrary, the Law on Personal Data Protection and Decree 356/2025/ND-CP tighten the position further by requiring consent to be given in respect of each purpose, prohibiting default consent mechanisms such as pre-ticked consent boxes and placing the burden of proving that consent on the data controller(1).

The second scenario is less conspicuous and, for that reason, more common. A business integrates a foreign AI System through an application programming interface to serve as an internal assistant or a document summarisation tool, and then sends customer data, including personal data, through it. Each such transmission is an act of processing and of transferring personal data abroad, and requires a cross-border data transfer impact assessment dossier as well as a written agreement setting out the purpose, the categories of data, the retention period and the responsibilities of the parties(2). In practice, many organisations and individuals remain insufficiently aware of this requirement to comply with it.

No royalties are payable for training an AI System for non-commercial purposes

The Law amending and supplementing a number of articles of the Law on Intellectual Property No. 131/2025/QH15, in force since 1 April 2026, added clause 5 to Article 7 of the current Law on Intellectual Property. That provision permits the use of text and data constituting subject matter of intellectual property rights that has been lawfully published for the purposes of scientific research, testing and the training of AI Systems, provided that such use does not unreasonably prejudice the rights and legitimate interests of authors and owners of intellectual property rights under that Law.

Under this provision, organisations and individuals may use publicly available repositories of content and data, including text and data protected by copyright and related rights, for scientific research, testing and the training of AI Systems without the consent of the author, the copyright owner or the related-rights owner, and without paying royalties. Under Decree 134/2026/ND-CP(3), however, the exception applies only where the following two sets of conditions are met.

  • The first set of conditions concerns the material itself: the text and data must (i) have been lawfully published to the public; (ii) have been accessed by lawful means from a lawful source; and (iii) not have been obtained by removing or circumventing the technological protection measures applied by the rights owner(4); and
  • The second set of conditions concerns the use itself: it must (i) be solely for the purposes of scientific research, testing and the training of AI Systems, and not for commercial purposes; (ii) not conflict with the normal exploitation of the text and data protected by copyright or related rights and not unreasonably prejudice the legitimate interests of the author, the copyright owner or the related-rights owner; and (iii) produce output that does not substitute for the market for, or the normal exploitation of, the protected subject matter and does not give rise to unfair competition in the exploitation and use of that subject matter(5).

In addition, organisations and individuals that use text and data protected by copyright or related rights to train an AI System must retain the technical records together with the training data, hold them available to the competent State authority for the purposes of verification, the resolution of disputes and the handling of related breaches, and respect the rights owner’s reservation of rights(6).

It should be noted that authors, copyright owners and related-rights owners are entitled to reserve their rights and to refuse the use of their text and data for the training of AI Systems, save where the conditions set out above are satisfied(7). Where organisations or individuals use text and data protected by copyright or related rights to train an AI System and subsequently exploit it commercially, they must pay royalties to the author, the copyright owner or the related-rights owner(8).

Accordingly, where the use does not satisfy all of the conditions set out above, it falls outside the exception. The use of protected text and data to train an AI System then requires the permission of the copyright owner and the related-rights owner and the payment of royalties, in accordance with the general principles of intellectual property law(9).

Copyright arises only where the human contribution can be proved

Article 5a, added to Decree 17/2023/ND-CP, resolves a question with which many legal systems still struggle, namely whether output created with the assistance of AI attracts copyright protection. It does, but only where the human contribution is substantial and decisive, demonstrated through the provision of input data, the setting of technical parameters and the assessment and selection of results, such that the output bears the personal imprint and the direct control of a human being rather than being the random product of an algorithm. Output generated entirely by AI gives rise to no copyright(10).

That test is consistent with international practice, but its strongest practical effect lies in the evidential burden that comes with it. A person claiming protection must declare the use of an AI system and, in the event of a dispute, produce evidence of human control, comprising the input data, the technical parameters or design documents, and the interaction history.

The interaction history is, in practical terms, the prompt log: the exchanges and interaction between the human user and the AI System in the course of producing the output. An advertising agency, a design studio or a software development team that uses AI in its production process without recording who used which tool, what was fed into it and how the result was edited will therefore be unable, once a dispute arises, to prove the decisive human contribution. Without that proof there is no copyright, which means that intangible assets the business has itself created may go unprotected.

Questions left open

The present framework still leaves matters that call for further study and refinement. The most pressing is the relationship between the right to request the erasure of personal data(11) and an AI System that has already been trained. Once data has been used in training and has become part of the AI model itself, erasing that particular data may be impossible with existing techniques, and the law has yet to clarify whether the erasure obligation stops at the training dataset or extends to the model and to the copies already deployed.

The boundary of “not for commercial purposes” is likewise undefined and may be difficult to determine in practice in certain cases. Take an AI System trained during a research phase, and therefore for a non-commercial purpose, which is subsequently commercialised: how is that to be characterised? Must the owner of the AI System, or the party that developed it, pay royalties to the author or the copyright owner for having used copyright-protected text and data during the earlier research and training phase?

There is, moreover, no dedicated decree on administrative sanctions in the field of artificial intelligence, so there is no direct basis for penalties and recourse must instead reply on the sanctioning decrees of the relevant sector legislation, where a corresponding breach exists. That makes it a matter of some urgency to issue rules on administrative sanctions in order to complete Vietnam’s legal framework for AI.

Conclusion

The issues discussed above share a common feature. Whether the obligation concerns the provenance of personal data, the conditions for using text and data protected by copyright, or the conditions for protecting AI-assisted output, the law requires the provenance of the material to be capable of proof and the process of use to comply with the applicable legislations. Consent from data subjects must be capable of proof, the sources of the data used to train an AI System must be capable of being produced, and the human contribution must be capable of verification.

The consequence is that the evidential file becomes a form of legal asset. Records of data provenance and of the conditions of use determine whether a business enjoys the exception or must pay royalties when it uses copyright-protected data for research, experimentation or the training of an AI System. Records of data subject consent determine whether the reuse of customer data for AI training is lawful, and prompt logs, together with the extent of the human contribution, determine whether AI-assisted output attracts copyright.


(1) Article 9.4(a) of the Law on Personal Data Protection No. 91/2025/QH15 (consent must be given in respect of each purpose); Articles 6.2 and 6.3 of Decree 356/2025/ND-CP (the burden of proving consent lies with the data controller; default consent mechanisms are prohibited); compare Article 6.1(f) GDPR

(2) Articles 20.1(b), 20.1(c) and 20.2 of the Law on Personal Data Protection No. 91/2025/QH15; Articles 18.2(b), 18.3(c) and 18.3(d) of Decree 356/2025/ND-CP

(3) Section 3 of Chapter III of Decree 17/2023/ND-CP, comprising Articles 37a, 37b and 37c, added by Decree 134/2026/ND-CP of 6 April 2026

(4) Article 37a.1 of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(5) Articles 37a.2(a), 37a.2(b) and 37a.2(c) of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(6) Article 37c.1 of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(7) Articles 37b.1, 37b.2 and 37b.3 of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(8) Article 37c.2 of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(9) Article 20.3 of the Law on Intellectual Property, under which the exploitation of economic rights requires the permission of the copyright owner and the payment of royalties, save in the cases provided for in Articles 25, 25a, 26, 32 and 33 of that Law

(10) Article 5a of Decree 17/2023/ND-CP, added by Decree 134/2026/ND-CP

(11) Articles 4.1(d) and 14.1 of the Law on Personal Data Protection No. 91/2025/QH15; Article 5.4 of Decree 356/2025/ND-CP on the time limits for giving effect to an erasure request

THAN TRONG LY

THAN TRONG LY

Partner of DIMAC Law Firm